A threat actor behind the Graphalgo campaign has expanded its reach beyond the JavaScript ecosystem, planting Go-based malware inside two Terraform providers and two Go Modules, marking the first documented case of malicious code distributed through the Terraform Registry.
Researchers at Aikido Security uncovered the operation, which links back to a crypto-recruiter scam campaign first flagged by ReversingLabs in February 2026 and echoed in recent reports from Safedep, CheckMarx, and JFrog.
The malicious packages Terraform providers gocommunity-io/dockerd and kreuzwenker/docker (a typosquat of the legitimate provider with 56 million downloads), plus Go Modules gocommunity.io/orderedbtree and gogets.dev/btreex, all carry a Go port of the Graphalgo malware.
Graphalgo Malware Hits Terraform Providers
The code shares blockchain infrastructure, Slack C2 channels, and a hardcoded public key with JavaScript samples distributed through NPM since April 2026, tying it directly to the same threat actor.
Rather than firing indiscriminately, the malware hides inside resource_docker_container_funcs.go and only activates when a SHA256 hash of specific Terraform variables matches a hardcoded value.
This gating behavior signals a targeted operation rather than opportunistic mass infection; the payload stays dormant unless triggered by very specific runtime conditions, then unzips and AES-decrypts a hidden archive before launching a second-stage Go agent via a detached go run . command.

The second-stage RAT reports system fingerprints to a Slack channel dubbed “frontend-devs,” then pivots to encrypted communications using ephemeral key exchanges.
Its real innovation is a blockchain dead drop on the Arbitrum Sepolia testnet, where infected clients exchange public keys and read encrypted commands from a smart contract every three seconds, with Slack polling occurring every 10 seconds.
Because compromised clients silently discard messages meant for others, the design minimizes leakage risk while still enabling bidirectional control a notably mature use of blockchain-based C2.
To lend legitimacy to its packages, the threat actor stood up companion websites gogets[.]dev and gocommunity[.]io mimicking new Go package registries, alongside GitHub organizations that periodically purge malicious commits to preserve account longevity.
One module, gogets.dev/btreex, even used forged, backdated commits to appear months older than its actual September 8 publish date, exploiting how Go Modules treats commit timestamps as authoritative.
Unlike typical developer-workstation attacks, compromising Terraform providers gives attackers a more direct route to DevOps machines with production cloud credentials.
Aikido’s telemetry shows at least 18 unique victim hostnames across Windows, Linux, and macOS systems since mid-July, suggesting a small but deliberately targeted campaign rather than a broad supply-chain sweep.
Organizations that installed any flagged package should isolate the affected machine immediately, rotate all credentials including cloud, GitHub, and SSH keys, audit recent Terraform applies and CI/CD activity, and fully reimage the host rather than simply removing the package, since the detached go run process may persist independently.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.