The Malware Hiding in Developer Tools That Turned Terraform Providers Into Attack Paths
Brief
Malware has moved into tools developers use to build and manage cloud infrastructure. A campaign linked to Graphalgo planted a remote access program in Terraform providers and Go software packages, turning routine development work into a possible route onto valuable machines.
The packages did not behave like obvious malicious downloads. Some waited for particular inputs before running hidden code, making casual testing less likely to reveal them.
The danger echoes earlier attacks using fake Terraform job tests , although this campaign used its own malicious packages and methods. Aikido analysts identified the Terraform and Go variants.
Aikido said in a report shared with Cyber Security News (CSN) that this was the first time its researchers had observed malware distributed through Terraform providers.
