# Malicious Go Malware Distributed via Terraform Providers and Go Modules

*Published September 25, 2026*
*Source: [https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html](https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/malicious-go-malware-distributed-via-terraform-providers-and-go-modules) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Cybersecurity experts have uncovered a new method of malware distribution involving the use of malicious Terraform providers and Go modules hosted on the HashiCorp registry. This marks the first instance of threat actors exploiting this centralized repository to spread Go-based malware. The operation shares similarities with the Graphalgo campaign, previously attributed to North Korean threat actors. 

The attackers approach developers through social media platforms like LinkedIn and Facebook, masquerading as representatives of fictitious Web3 companies. They offer coding tasks that introduce harmful code via dependencies published on npm or PyPI. Recently, a new wave of malicious npm packages was discovered, demonstrating similar strategies.

The malware is sophisticated, decrypting its payload only under specific cryptographic conditions. This targeted approach is further indicated by the malware's ability to interact with an Ethereum smart contract and maintain communication through a Slack channel. The malware collects system information and communicates with the attackers using shared keys generated from public-private key pairs, ensuring secure command-and-control operations.

The use of Terraform providers presents a novel tactic, offering direct access to sensitive credentials. Although not the first time North Korean actors have used this method, it signifies an expansion of their campaign beyond npm and PyPI. The recent discovery by security firm CloudSEK of a JavaScript loader, named GHAPPIER, further highlights the ongoing threat. This loader was distributed following the compromise of a legitimate npm package and demonstrated the threat actors' capability to dynamically alter payloads.

This development underscores the evolving tactics of DPRK-linked threat actors who continually adapt their methods to broaden their reach and impact.
