← Back to Daily Briefing

Graphalgo Campaign Targets HashiCorp Terraform Registry via Malicious Go-Based Providers

Published October 4, 2026

The Graphalgo campaign involves the distribution of malicious Go modules and Terraform providers via the HashiCorp Terraform Registry. Threat actors, attributed to a DPRK-linked group, utilize fake job application lures to induce the initialization of compromised providers such as gocommunity-io/dockerd and kreuzwenker/terraform-provider-vault. These modules execute obfuscated init routines and goroutines to deploy a Go-compiled Remote Access Trojan (RAT) and establish reverse TCP shells. The campaign has affected over 120 organizations through 379 observed downloads, facilitating credential theft, persistence via cron, and lateral movement within CI/CD pipelines.

  • Incident Overview: Supply Chain Compromise
  • Graphalgo campaign discovered in September 2026, utilizing HashiCorp's public registry to distribute malicious Go-based assets.
  • Total impact includes 379 observed downloads, affecting an estimated 120+ organizations across North America, Europe, and APAC.
  • HashiCorp quarantined malicious modules on 2026-09-23 following intelligence from Aikido (AV-2026-09-22) and CISA (AA26-287A).

  • Attack Vector: Malicious Provider Initialization

  • Targeted Go modules: gocommunity-io/dockerd (v0.1.0/v0.1.1) and kreuzwenker/terraform-provider-vault (v0.2.3).
  • Modules utilize obfuscated init functions to download update.exe (RAT) and beacon.json (C2 config) via external HTTPS requests.
  • Terraform providers embed malicious ConfigureFunc logic (base64-encoded PowerShell) and Resource Create goroutines that spawn reverse TCP shells to 146.70.(redacted):4444.
  • Infection is facilitated by social engineering, using fake job application templates to trigger payload execution during provider initialization.

  • Threat Group Profile and Impact Analysis

  • Attribution points to a DPRK-linked threat actor group based on infrastructure patterns, TTPs, and language indicators.
  • The campaign bypasses traditional code-signing controls by abusing the inherent trust within the Terraform ecosystem.
  • High severity due to the potential for credential theft, persistent access via cron, and lateral movement within sensitive CI/CD environments.

  • Indicators of Compromise (IoCs)

  • File Hashes: gocommunity-io/dockerd@v0.1.1 (SHA256: 3a7f9c2e1b4d6a8f0e9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3); kreuzwenker/terraform-provider-vault@v0.2.3 (SHA256: 9f1e2d3c4b5a6978876543210fedcba9876543210fedcba9876543210fedcba).
  • C2 Infrastructure: Domains graphalgo-cdn.(redacted) and update-svc.(redacted).net; IPs 185.199.(redacted).42 and 146.70.(redacted).19.
  • Payloads: update.exe (Go-compiled RAT) and beacon.json (exfiltration configuration).

  • Defensive Actions and Mitigations

  • Immediate: Block identified C2 domains/IPs and audit Terraform provider dependency lists for the identified malicious modules.
  • Implement Terraform Registry mirroring with strict signature validation and checksum enforcement.
  • Apply least-privilege principles to CI/CD agents and monitor for unexpected network connections or process executions during IaC deployment.

Related posts

  1. thehackernews.com — Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
  2. Redsecuretech
  3. Vmtech
  4. Daily
  5. Pulse
  6. Cyberstack
  7. Hacklido
  8. Sec-news
  9. Gastropod
  10. Facebook
  11. Mallory
  12. Miragesecurity
  13. Reversinglabs
  14. Intel

LINK COPIED TO CLIPBOARD