Security researchers have identified Go malware distributed through two Terraform providers and two Go modules, expanding a software supply-chain campaign into infrastructure tooling. Aikido disclosed the findings on September 22 and linked the code and command infrastructure to the Graphalgo malware family.
Targeted activation and dual command channels
The affected Terraform providers were published under the names gocommunity-io/dockerd and kreuzwenker/docker; the second name closely resembles the legitimate kreuzwerker provider. Aikido says hidden entry points activate only when specific input values produce a matching cryptographic hash, behavior consistent with a targeted delivery mechanism rather than indiscriminate execution.
The recovered Go agent gathers basic host information and uses encrypted communications over Slack and an Ethereum test network. Researchers also identified related Go modules and fake package ecosystems intended to make the developer infrastructure appear credible. The investigation did not establish every action performed on affected hosts, so claims about downstream impact should remain limited to the observed capabilities and indicators.
Why Terraform raises the stakes
Terraform commonly runs on developer workstations and CI/CD systems that can access cloud and production credentials. Organizations that installed the named providers or modules should isolate affected systems, rotate exposed credentials and review infrastructure changes made during the exposure window. More broadly, teams should verify provider publishers and lock files before allowing infrastructure code into trusted pipelines. SectechMedia follows these risks through its cyber-physical security channel.

Leave a Reply