The Malware Hiding in Developer Tools That Turned Terraform Providers Into Attack Paths
Malware campaign distributes remote access tools via malicious Terraform providers and Go packages, using Slack and Ethereum smart contracts for command and control.
A malicious campaign linked to the threat actor Graphalgo has been discovered distributing remote access malware via compromised Terraform providers and Go software packages. The malicious packages, which included a typosquatted Terraform provider, used complex activation triggers to hide their payloads and avoid detection. Once activated, the malware collected system information and communicated with command and control servers via Slack and Ethereum smart contract transactions. Researchers at Aikido identified the campaign and noted it represents the first observed malware distribution through Terraform providers.