Graphalgo Malware Uses Malicious Terraform Providers and Go Modules to Deploy RAT
Graphalgo malware expands supply-chain attacks to Terraform providers and Go modules, using Slack and blockchain for C2.
The Graphalgo malware campaign has expanded its supply-chain attack vector beyond npm and PyPI to include malicious Terraform providers and Go modules. This marks the first observed case of malware distribution through Terraform providers, directly targeting infrastructure-as-code workflows. The malware deploys a Go-based RAT that uses Slack API and Arbitrum Sepolia testnet blockchain for command-and-control, with activation gated by cryptographic hashes to target specific victims.
75