Researchers have disclosed Go-based malware distributed through two Terraform providers and two Go modules on the HashiCorp Registry, marking the first time the centralized repository has been used as a vector for malicious payloads. The flagged packages include gocommunity-io/dockerd and kreuzwenker/docker, along with gocommunity.io/orderedbtree and gogets.dev/btreex.
The malware shares infrastructure with the Graphalgo campaign attributed to North Korean actors. It collects system information and then establishes dual command-and-control channels: one via a Slack bot token and another by polling an Ethereum smart contract on a testnet. The encrypted payload only decrypts under specific conditions, which researchers say is characteristic of a targeted operation.
According to Aikido, the Terraform providers represent a novel tactic that can provide a more direct path to production credentials. However, this is not the first time North Korean adversaries have abused Terraform-related infrastructure; SentinelOne recently detailed TraderTraitor using weaponized Terraform lock files to deliver Rust backdoors. The campaign's use of fake job interviews as an initial access vector remains consistent with earlier operations.