Graphalgo Malware Reaches Terraform Providers for the First Time
Security / news
Graphalgo Malware Reaches Terraform Providers for the First Time
Two fake Terraform providers and two Go modules polled an Ethereum contract every 3 seconds as a backup channel, security firm Aikido said, describing the campaign's first use of HashiCorp's registry.

An attacker who can get a victim to run terraform init against one of two fake providers, or import one of two Go modules, gains a foothold that waits silently for a specific trigger before it phones home over a blockchain, according to a Sept. 23 report from security firm Aikido. It is the first time researchers have seen the campaign, tracked as Graphalgo, reach HashiCorp's Terraform Registry.
Aikido said the two Terraform providers, gocommunity-io/dockerd and kreuzwenker/docker, a typosquat of the legitimate kreuzwerker/docker provider, drew 222 and 1,449 downloads respectively before being flagged. Two Go modules, gocommunity.io/orderedbtree and gogets.dev/btreex, published Aug. 11 and Sept. 8, carried the same payload family. The Hacker News reported that neither article found any statement from HashiCorp about removing the providers or issuing an advisory.
A blockchain channel that polls every 3 seconds
The malware's primary command channel is an Ethereum smart contract deployed on the Arbitrum Sepolia test network, at address 0xAD02b5cDE693529d3bdA0266299501ad0193036C. Infected machines poll the contract's serviceData1 and serviceData2 fields every 3 seconds and decrypt whatever they contain using the contract's setCPubKey method. A researcher at security firm SafeDep, cited in Aikido's report, said "the blockchain path also decrypts remote data, writes subwatcher, and starts it with Node.js."
A second channel hides inside two Slack workspaces
Alongside the blockchain, the malware checks in with a Slack workspace at portfolio-devs.slack.com, in a channel called #frontend-devs, then takes commands from a second workspace, portfolio-testers.slack.com, in #qa-announcements, polling every 10 seconds. Messages are encrypted with keys derived from a threat-actor public key that first surfaced in npm packages in April 2026.

Built to run dormant until one condition is met
Neither the Terraform providers nor the Go modules activate immediately. The Terraform payload checks whether the SHA256 hash of a victim's containerName and networkID values, concatenated, matches a single hardcoded hash before it does anything. The gogets.dev/btreex module activates only when it processes an object carrying a specific integer value in a price field. Aikido said that design points to a small, deliberately chosen set of targets rather than a mass campaign.
Eighteen machines, not thousands
Across the infrastructure Aikido examined, the malware logged 725 check-in messages from 18 unique hostnames: 3 running Windows, 5 Linux and 10 macOS. The earliest activity Aikido traced back to July 16, 2026.
The same key traced back to February
The public key used in the Slack channel matches one ReversingLabs first documented in February 2026, in an npm package called modern-events, in a campaign later linked to North Korea. Other packages in that lineage include indexed-btree, mathsbase, math-universe, crypto-hasher and graphlib-js; one, version 0.2.21, stayed live on npm for only 35 minutes and 38 seconds on Sept. 9 before it was pulled. Neither Aikido nor The Hacker News named the specific accounts behind the Terraform and Go packages, or said whether they were linked to the same publisher identities as the earlier npm packages.
| Package | Registry | Metric |
|---|---|---|
| kreuzwenker/docker | Terraform Registry | 1,449 downloads |
| gocommunity-io/dockerd | Terraform Registry | 222 downloads |
| gocommunity.io/orderedbtree | Go module | Published Aug. 11, 2026 |
| gogets.dev/btreex | Go module | Published Sept. 8, 2026 |
The Terraform Registry has not previously carried a confirmed malware distribution case, which is why Aikido flagged this instance rather than folding it into its running count of npm and PyPI incidents. The pattern echoes the DPRK-linked attacks on Rust's crates.io registry disclosed in September, and the Shai-Hulud worm that returned to npm the same month, both aimed at developers who trust a registry's namespace more than they verify a specific maintainer.
Sources
More in Security
- 01Siemens' Edge Platform Still Carried a Keycloak Bug Fixed in AugustCISA published the advisory on Sept. 22, more than a month after Red Hat shipped the upstream fix, because four Siemens Industrial Edge Management products bundle the identity server.
- 02LuaRocks Patches a Bytecode Flaw Attackers Used for Six WeeksAn independent researcher's writeup, published a day after the fix, names the LuaJIT instruction that let a crafted package listing read and write server memory.
- 03CISA's WSO2 Catalog Entry Names the Wrong VulnerabilityThe agency's Sept. 24 addition of CVE-2026-5430 borrows language from a different, four-year-old WSO2 flaw, even as watchTowr reports live attacks forging admin tokens through the real one.
- 04Microsoft's SharePoint 'Spoofing' Bug Is Really an RCE FlawCVE-2026-65660 sat rated 6.5 for weeks until a Viettel researcher showed it grants remote code execution, and CISA added it to its exploited-vulnerabilities catalog Sept. 25 after attackers began installing webshells.