Developer Supply-Chain Attacks Hit Terraform and MemTensor Packages
On 23 September 2026, researchers disclosed Graphalgo malware in Terraform providers and a separate MemTensor sckit stealer on npm and PyPI.
On 2026-09-23, Cyber Security News, GBHackers, and The Hacker News reported that Aikido found the first observed malware distributed through Terraform providers: a Graphalgo campaign planting a Go remote-access tool in providers and Go packages or modules. The Hacker News, citing Aikido, named HashiCorp Registry providers gocommunity-io/dockerd (222 downloads) and kreuzwenker/docker (1,449 downloads) and Go modules gocommunity.io/orderedbtree and gogets.dev/btreex, while Cyber Security News described a typosquatted provider and infections on 18 Windows, Linux, and Mac hostnames. The implant collects system information and uses Slack plus an Ethereum contract on the Arbitrum Sepolia testnet; The Hacker News says it can execute Go or JavaScript, and GBHackers says activation is cryptographically hash-gated, which other reports describe only as complex triggers. Attribution is not uniform: Cyber Security News and GBHackers name Graphalgo without a state link, whereas The Hacker News says the payloads overlap a campaign ReversingLabs attributed to North Korean operators who use fake Web3 jobs. Separately, The Hacker News reported compromised MemTensor npm and PyPI packages—@memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, and 0.1.25, and MemoryOS 2.0.34—delivering the Go stealer sckit after publish tokens were taken from GitHub Actions, and none of the reports ties sckit to Graphalgo. sckit targets Windows, Linux, and macOS, steals AWS, GCP, GitHub, GitLab, registry, and developer-tool credentials, and can republish itself; The Hacker News also said related npm packages were flagged and that SentinelOne separately described TraderTraitor using weaponized Terraform lock files.
- On 2026-09-23 Aikido was credited with finding the first reported malware spread through Terraform providers, tied by outlets to the Graphalgo campaign and a Go remote-access implant in providers and Go packages or modules.
- The Hacker News, citing Aikido, named HashiCorp Registry providers gocommunity-io/dockerd (222 downloads) and kreuzwenker/docker (1,449 downloads), plus Go modules gocommunity.io/orderedbtree and gogets.dev/btreex.
- Cyber Security News reported a typosquatted provider and infections on 18 hostnames across Windows, Linux, and Mac; GBHackers says activation is gated by cryptographic hashes.
- Command and control uses Slack and an Ethereum smart contract on the Arbitrum Sepolia testnet; The Hacker News says the implant collects system details and can run Go or JavaScript.
- Attribution differs: Cyber Security News and GBHackers name Graphalgo only, while The Hacker News says payloads overlap a campaign ReversingLabs linked to North Korean operators using fake Web3 job offers.
- Separately, compromised MemTensor packages delivered the Go stealer sckit: @memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, and 0.1.25, and MemoryOS 2.0.34, after GitHub Actions publish tokens were stolen. No report links sckit to…
- sckit targets Windows, Linux, and macOS, steals AWS, GCP, GitHub, GitLab, registry, and developer-tool credentials, exfiltrates them, and can republish; SentinelOne separately described TraderTraitor Terraform lock files.
Coverage timelineoldest first · each row is one article
- · 3d agoThe Malware Hiding in Developer Tools That Turned Terraform Providers Into Attack Paths
Cyber Security News· 75
Malware campaign distributes remote access tools via malicious Terraform providers and Go packages, using Slack and Ethereum smart contracts for command and control.
- · 3d agoGraphalgo Malware Uses Malicious Terraform Providers and Go Modules to Deploy RAT
GBHackers· 75
Graphalgo malware expands supply-chain attacks to Terraform providers and Go modules, using Slack and blockchain for C2.
- · 3d ago