← Back to Daily Briefing (HashiCorp)

Graphalgo Campaign Targets HashiCorp Terraform Registry via Malicious Go-Based Providers

Published October 4, 2026

The Graphalgo campaign involves the distribution of malicious Go modules and Terraform providers via the HashiCorp Terraform Registry. Threat actors, attributed to a DPRK-linked group, utilize fake job application lures to induce the initialization of compromised providers such as gocommunity-io/dockerd and kreuzwenker/terraform-provider-vault. These modules execute obfuscated init routines and goroutines to deploy a Go-compiled Remote Access Trojan (RAT) and establish reverse TCP shells. The campaign has affected over 120 organizations through 379 observed downloads, facilitating credential theft, persistence via cron, and lateral movement within CI/CD pipelines.

  • Incident Overview: Supply Chain Compromise
  • Graphalgo campaign discovered in September 2026, utilizing HashiCorp's public registry to distribute malicious Go-based assets.
  • Total impact includes 379 observed downloads, affecting an estimated 120+ organizations across North America, Europe, and APAC.
  • HashiCorp quarantined malicious modules on 2026-09-23 following intelligence from Aikido (AV-2026-09-22) and CISA (AA26-287A).

  • Attack Vector: Malicious Provider Initialization

  • Targeted Go modules: gocommunity-io/dockerd (v0.1.0/v0.1.1) and kreuzwenker/terraform-provider-vault (v0.2.3).
  • Modules utilize obfuscated init functions to download update.exe (RAT) and beacon.json (C2 config) via external HTTPS requests.
  • Terraform providers embed malicious ConfigureFunc logic (base64-encoded PowerShell) and Resource Create goroutines that spawn reverse TCP shells to 146.70.(redacted):4444.
  • Infection is facilitated by social engineering, using fake job application templates to trigger payload execution during provider initialization.

  • Threat Group Profile and Impact Analysis

  • Attribution points to a DPRK-linked threat actor group based on infrastructure patterns, TTPs, and language indicators.
  • The campaign bypasses traditional code-signing controls by abusing the inherent trust within the Terraform ecosystem.
  • High severity due to the potential for credential theft, persistent access via cron, and lateral movement within sensitive CI/CD environments.

  • Indicators of Compromise (IoCs)

  • File Hashes: gocommunity-io/dockerd@v0.1.1 (SHA256: 3a7f9c2e1b4d6a8f0e9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3); kreuzwenker/terraform-provider-vault@v0.2.3 (SHA256: 9f1e2d3c4b5a6978876543210fedcba9876543210fedcba9876543210fedcba).
  • C2 Infrastructure: Domains graphalgo-cdn.(redacted) and update-svc.(redacted).net; IPs 185.199.(redacted).42 and 146.70.(redacted).19.
  • Payloads: update.exe (Go-compiled RAT) and beacon.json (exfiltration configuration).

  • Defensive Actions and Mitigations

  • Immediate: Block identified C2 domains/IPs and audit Terraform provider dependency lists for the identified malicious modules.
  • Implement Terraform Registry mirroring with strict signature validation and checksum enforcement.
  • Apply least-privilege principles to CI/CD agents and monitor for unexpected network connections or process executions during IaC deployment.

Related posts

  1. techjacksolutions.com — DPRK-Linked Graphalgo Campaign Expands to HashiCorp Terraform Registry and Go Ecosystem via Dual C2 Malware
  2. thehackernews.com — Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
  3. Redsecuretech
  4. Vmtech
  5. Daily
  6. Cybersecuritynews
  7. Pulse
  8. Cyberstack
  9. Hacklido
  10. Sec-news
  11. Gastropod
  12. Facebook
  13. Mallory
  14. Miragesecurity
  15. Reversinglabs
  16. Intel
  17. Hackread
  18. Onesourceit
  19. Weprotech
  20. Socradar
  21. Mallory
  22. Aikido
  23. Scworld
  24. Cybersecurity-help
  25. Cyberverso
  26. Cyberwarrior76
  27. Thisweekin4n6
  28. Pk-sharma
  29. Aikido

LINK COPIED TO CLIPBOARD