Hackers Abuse Trusted Terraform Workflows to Infect Developer Systems With Cross-Platform Malware
A trojanized Terraform AWS provider installs FLATROOF and ROOFDECK malware on developer macOS, Linux, and Windows systems.
Zscaler ThreatLabz reported a July 2026 supply-chain campaign that uses a Go-based fake AWS Terraform provider, terraform-provider-awsbeta_v1.0.0, to launch malware when the provider loads. A Bash loader named safari_updater selects macOS, Linux, or Windows payloads hidden after decoy data in .woff files, then Base64-decodes and AES-256-CBC decrypts them. The payload is assessed as FLATROOF, a Rust backdoor with stealers for browsers, keychains, credentials, and crypto wallets, plus ROOFDECK, which can find its server through Pastebin or Nostr. Researchers saw tooling overlap with TraderTraitor, also known as Jade Sleet, but said evidence was insufficient for high-confidence attribution.
- Trojanized terraform-provider-awsbeta runs malicious Go code when Terraform loads the provider.
- Loader safari_updater downloads OS-specific payloads disguised as encrypted .woff font files.
- FLATROOF backdoor steals browser data, macOS keychains, Windows credentials, and crypto wallets.
- ROOFDECK locates command-and-control servers via Pastebin records or Nostr profile metadata.
- Zscaler notes possible TraderTraitor overlap but will not attribute with high confidence.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | arusupport-region1-webhook.online | gins/fonts/v1104/ FLATROOF payload download URL URL hxxps://arusupport-region1-webhook[.]online/statics/cache/v11/abicfjej FLATROOF command-and-control s |
| domain | githubusercontent.com | cs/cache/v11/ FLATROOF payload download URL URL hxxps://raw.githubusercontent[.]com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/f |
| domain | hashicorp-terraform.io | a899ad54 update.exe , Windows ROOFDECK URL hxxps://diagnose.hashicorp-terraform[.]io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7c |
| domain | pastebin.com | 11/abicfjej FLATROOF command-and-control server URL hxxps://pastebin[.]com/raw/3yptBDhL ROOFDECK Pastebin dead-drop URL Domain delay |
| domain | serveftp.com | cbaa7797e8a Bash loader download URL URL hxxps://supportaru.serveftp[.]com/statics/cache/v11/ FLATROOF payload download URL URL hxxp |
| domain | servehttp.com | m/raw/3yptBDhL ROOFDECK Pastebin dead-drop URL Domain delay.servehttp[.]com ROOFDECK command-and-control server Note: IP addresses an |
Full article943 words · extracted from cybersecuritynews.com · click to collapse
A newly identified supply-chain campaign is abusing Terraform provider workflows to infect developer systems with malware built for macOS, Linux, and Windows.
The activity uses a trojanized Terraform provider that appears to be a legitimate AWS-related plugin, allowing it to run malicious code while still behaving like a normal provider.
The campaign is a major concern for cloud engineers, DevOps teams, and cryptocurrency or Web3 developers because Terraform providers run on workstations and CI/CD systems that may hold source-code access, cloud credentials, API keys, deployment permissions, and browser-stored login data.
The case closely follows earlier reports on fake Terraform job tests used to compromise developers through trusted-looking infrastructure projects.
Researchers from Zscaler ThreatLabz identified the malware campaign in July 2026 and linked its tools and targeting patterns to suspected TraderTraitor activity. TraderTraitor is also tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces.
However, Zscaler said it did not have enough unique code, infrastructure, or cryptographic evidence to attribute this campaign to the group with high confidence.
The initial file, named terraform-provider-awsbeta_v1.0.0, is written in Go and poses as an Amazon Web Services provider for HashiCorp Terraform.
It contains a working provider structure, helping it appear normal to a victim. At the same time, an added malicious package runs as soon as Terraform loads the provider.
Hackers Abuse Trusted Terraform Workflows
The provider checks for a session.lock file in the temporary directory, downloads a Bash loader if that file is absent, runs it in the background, and then creates the lock file to avoid running twice.
The Bash loader, called safari_updater, checks the operating system and CPU architecture before selecting a tailored payload. It supports macOS, Linux, and Windows systems that use a compatible Unix-like shell, including Cygwin, MinGW, or MSYS.
The loader downloads files disguised as normal .woff web-font files, a method that can make the payload look less suspicious during a quick file review.
.webp)
The malicious files contain decoy font content followed by an @@ENDFONT@@ marker and an encrypted executable. The loader extracts the hidden data, Base64-decodes it, and decrypts it with AES-256-CBC.
It can use Python, Node.js, Perl, or OpenSSL, depending on which tool is installed on the victim device. On macOS, it also removes the quarantine attribute and applies an ad hoc code signature before execution, helping the malware run without normal Gatekeeper warnings.
The delivered malware is assessed to be FLATROOF, a Rust-based backdoor that supports all three major desktop operating systems. It can establish persistence through a Linux service, macOS logout configuration, or a Windows Registry Run value.
FLATROOF & ROOFDECK
FLATROOF can collect system information, list processes, manage files, execute commands, download follow-on payloads, upload stolen data, and remove itself when needed.
Its Python-based data stealers search for Chromium and Firefox browser data, including saved credentials, cookies, browsing history, autofill data, shell history, installed applications, running processes, and the current username.
On macOS, the malware can collect Safari data and the login.keychain-db file. On Windows, it targets Chrome, Edge, Brave, Windows Credential Manager entries, command history, and wallet-extension data from MetaMask, Phantom, Trust Wallet, and Rabby.
This browser and wallet focus resembles developer package supply-chain threats that have increasingly targeted Web3 environments. The campaign also deploys ROOFDECK, a Windows and macOS backdoor with stronger remote-control functions.
.webp)
ROOFDECK can discover files and disks, run shell commands, transfer files, read and write clipboard data, manage background tasks, update itself, and erase traces.
Its command-and-control discovery process is especially notable: it can use a local configuration file, a cryptographically signed Pastebin record, or Nostr profile metadata to locate its active server.
This use of public platforms as flexible delivery or control layers is similar to other malware server hiding methods seen in developer-focused campaigns.
For defenders, the incident shows why provider verification must be part of Terraform security. Teams should restrict unapproved providers, validate checksums in Terraform lock files, review provider source addresses, and block lookalike domains.
Security teams should also watch for Terraform-related processes launching shells, unexpected files in temporary directories, suspicious .woff downloads, and executables running from user profile folders.
Applying secure CI/CD pipeline practices can further reduce the risk by adding code review, dependency controls, secret management, and automated scanning before infrastructure changes are deployed.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-1 | 9d78ece09457907b730d139e4e0c64dd | terraform-provider-awsbeta_v1.0.0 trojanized Terraform provider |
| SHA-1 | 73adaea97f003735335505858c1c6def | safari_updater Bash loader |
| SHA-1 | 116f7189ed7b41f1b339a749d56e63be | HiraginoSans-Bold.woff, encrypted macOS x86_64 FLATROOF |
| SHA-1 | be60c52ca8a01fef7dc15c2f0ebb77d8 | HiraginoSans-Regular.woff, encrypted macOS ARM64 FLATROOF |
| SHA-1 | 58fa0d651898446d5f5d2ed8a27a3330 | MalgunGothic-Bold.woff, encrypted Windows PE32+ FLATROOF |
| SHA-1 | 2621753691be9521288664bb551dfba6 | MalgunGothic-Italic.woff, encrypted Windows PE32 FLATROOF |
| SHA-1 | ad0b1b6d2c8b9d09d6473a4a299470ab | NotoSansCJK-Bold.woff, encrypted Linux x86-64 FLATROOF |
| SHA-1 | 4b8509cde757b5428e5f99c8dffe73ca | NotoSansCJK-ExtraBold.woff, encrypted Linux ARM FLATROOF |
| SHA-1 | 3826dc7a9ba8bd5b1c143560c1530d89 | NotoSansCJK-Italic.woff, encrypted Linux x86 FLATROOF |
| SHA-1 | 34a52e6a4d803e94fe497bab682abfd3 | NotoSansCJK-Regular.woff, encrypted Linux ARM64 FLATROOF |
| SHA-1 | 2b81aceab0142472d94eb42e500b27b1 | imagent, macOS ROOFDECK |
| SHA-1 | 9d88b4494c7bc27b10358b68a899ad54 | update.exe, Windows ROOFDECK |
| URL | hxxps://diagnose.hashicorp-terraform[.]io/plugins/grpc/v6/schema/metrics/333afe63-c5a2-43f0-b046-7cbaa7797e8a | Bash loader download URL |
| URL | hxxps://supportaru.serveftp[.]com/statics/cache/v11/ | FLATROOF payload download URL |
| URL | hxxps://raw.githubusercontent[.]com/bluearuhost/hospitalrun-frontend/refs/heads/main/public/fonts/version1/ | FLATROOF GitHub download URL |
| URL | hxxps://stage-fashion365.vercel[.]app/static/tinymce4.7.5/plugins/fonts/v1104/ | FLATROOF payload download URL |
| URL | hxxps://arusupport-region1-webhook[.]online/statics/cache/v11/abicfjej | FLATROOF command-and-control server |
| URL | hxxps://pastebin[.]com/raw/3yptBDhL | ROOFDECK Pastebin dead-drop URL |
| Domain | delay.servehttp[.]com | ROOFDECK command-and-control server |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.