#Graphalgo
"Graphalgo campaign spreads to Terraform providers and Go Modules" published by Aikido. #GitHub, #Graphalgo https://www.aikido.dev/blog/graphalgo-terraform-go-modules
Graphalgo campaign spreads to Terraform providers and Go Modules
www.aikido.dev
September 23, 2026 at 2:15 AM
📢 Campagne Graphalgo : malware Go distribué via des providers Terraform et des modules Go

Cet article présente une analyse technique détaillée d'une extension de la campagne Graphalgo, initialement rapportée par ReversingLabs en…

🟢 vérification factuelle haute
#Graphalgo #Terraform #Cyberveille
Campagne Graphalgo : malware Go distribué via des providers Terraform et des modules Go
Cet article présente une analyse technique détaillée d'une extension de la campagne Graphalgo, initialement rapportée par ReversingLabs en février 2026. C'est la première fois que des malwares sont distribués via des providers Terraform.
cyberveille.ch
September 23, 2026 at 9:00 PM
Aikido found the first malware they've seen shipped as Terraform providers. kreuzwenker/docker typosquats kreuzwerker/docker, which has 56 million downloads. One letter apart. Check your lock files.
www.aikido.dev/blog/grapha...
Graphalgo Malware Spreads to Terraform and Go
Aikido found Graphalgo-linked Go malware in Terraform providers and Go Modules, using targeted triggers, Slack, and blockchain C2.
www.aikido.dev
September 26, 2026 at 11:14 PM
#Graphalgo Scam: North Korean Lazarus hackers are using fake Florida LLCs, mimicking SWFT Blockchain, and using #GitHub typosquatting to target developers with malware.

Read: hackread.com/graphalgo-sc...

#CyberSecurity #NorthKorea #Lazarus #Blockchain #Scam
GraphAlgo Scam: Lazarus Hackers Register Real US LLCs to Spread Malware
Lazarus hackers revive the GraphAlgo scam, registering real US LLCs to trick crypto developers into running malware via fake job tests.
hackread.com
April 10, 2026 at 4:59 PM
Graphalgo hid malware in Terraform providers & Go modules—Slack, blockchain & trigger-based payloads now part of the game. #Malware #DevTools #Terraform #GoModules #Graphalgo #CloudSecurity https://thedailytechfeed.com/terraform-providers-hijacked-malware-lurking-in-dev-tools/
September 23, 2026 at 9:40 AM
Attackers use #Terraform Registry as a #malware channel. Two malicious providers delivered Go malware with #Slack and #blockchain command channels, extending a campaign already seen across npm and PyPI. Infrastructure as code is now "infection as code":
👇
Graphalgo Malware Spreads to Terraform and Go
Aikido found Graphalgo-linked Go malware in Terraform providers and Go Modules, using targeted triggers, Slack, and blockchain C2.
www.aikido.dev
September 25, 2026 at 8:56 AM
Lazarus turned the Terraform Registry into a malware drop - a typosquatted Docker provider hides a Go RAT. https://intel.threadlinqs.com/threat/TL-2026-2635 #ThreatIntel #Graphalgo #Contagious #PolinRider
September 24, 2026 at 1:27 AM
The latest update for #AikidoSecurity includes "Cyber Resilience Act is here! Myth busting and first impressions" and "Graphalgo campaign spreads to Terraform providers and Go Modules".

#Cybersecurity #AppSec #DevSecOps https://opsmtrs.com/48vGyRP
Aikido
Aikido Security is an automated application security platform designed specifically for software engineering teams.
opsmtrs.com
September 23, 2026 at 4:27 AM
Go-based malware is distributed via HashiCorp’s centralized module and Terraform provider repositories, overlapping with Graphalgo attributed to DPRK actors.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 23, 2026 at 8:04 PM
Whoa Morty. Graphalgo just put Go malware in HashiCorp's Terraform registry. Typosquat kreuzwenker/docker next to the real kreuzwerker, plus gocommunity-io/dockerd. Trigger hash, Slack and Arbitrum dead drops. Your infra apply is the interview. day267.014
September 24, 2026 at 4:36 AM
✨ Provider Terraform malevoli e il malware Graphalgo: la nuova minaccia supply-chain per i team DevOps
Leggi il blog: spcnet.it/provider-ter...

💬 Se ne può parlare sul forum: internet-forum.it
September 24, 2026 at 3:58 PM
Graphalgoマルウェア、新たなサプライチェーン攻撃でTerraformおよびGoパッケージを標的に

セキュリティ研究者らが、2つのTerraformプロバイダーと2つのGoモジュールにGraphalgo関連のマルウェアを発見しました。今回のキャンペーンは、以前npmパッケージで確認された脅威を拡張したもので、通常利用時にはマルウェアを非活性状態に保つ隠しトリガーを使用しています。 Aikido Securityによ
Graphalgoマルウェア、新たなサプライチェーン攻撃でTerraformおよびGoパッケージを標的に
セキュリティ研究者らが、2つのTerraformプロバイダーと2つのGoモジュールにGraphalgo関連のマルウェアを発見しました。今回のキャンペーンは、以前npmパッケージで確認された脅威を拡張したもので、通常利用時にはマルウェアを非活性状態に保つ隠しトリガーを使用しています。 Aikido Securityによ
blackhatnews.tokyo
September 23, 2026 at 8:02 AM
Graphalgoマルウェア、悪意あるTerraformプロバイダーとGoモジュールを悪用してRATを展開

継続中のGraphalgoソフトウェアサプライチェーン攻撃キャンペーンに関連する脅威アクターが、npmおよびPyPIの枠を超えて活動範囲を拡大していることが分かりました。悪意あるTerraformプロバイダーとGoモジュールを使い、Go言語で書かれた標的型リモートアクセス型トロイの木馬(RAT)を配布しています。 今
Graphalgoマルウェア、悪意あるTerraformプロバイダーとGoモジュールを悪用してRATを展開
継続中のGraphalgoソフトウェアサプライチェーン攻撃キャンペーンに関連する脅威アクターが、npmおよびPyPIの枠を超えて活動範囲を拡大していることが分かりました。悪意あるTerraformプロバイダーとGoモジュールを使い、Go言語で書かれた標的型リモートアクセス型トロイの木馬(RAT)を配布しています。 今
blackhatnews.tokyo
September 23, 2026 at 10:07 AM
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
thehackernews.com/2026/09/atta...
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Malicious Terraform providers and Go modules deliver Graphalgo-linked Go malware using blockchain and Slack for command and control.
thehackernews.com
September 23, 2026 at 9:45 PM
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
thehackernews.com/2026/09/atta...
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Malicious Terraform providers and Go modules deliver Graphalgo-linked Go malware using blockchain and Slack for command and control.
thehackernews.com
September 23, 2026 at 8:05 PM
HashiCorpレジストリ経由でGoマルウェアが配信される。TerraformプロバイダーとGoモジュールが悪用された。
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Malicious Terraform providers and Go modules deliver Graphalgo-linked Go malware using blockchain and Slack for command and control.
thehackernews.com
September 23, 2026 at 9:25 PM
The Graphalgo campaign returns using fake job interviews, cloned GitHub orgs, and typo-squatted repos to deliver encrypted downloaders and RATs targeting crypto developers. Evidence points to North Korean state sponsorship. #Graphalgo #NorthKorea
Graphalgo fake recruiter campaign returns
The graphalgo campaign uses fake job interviews, cloned GitHub organizations, typo‑squatted repositories and crafted GitHub release artifacts to deliver an encrypted multi-stage downloader and a RAT to targeted crypto developers. Evidence including GMT+9 commit timestamps, reused RAT payloads, Git history rewriting and the creation of a Florida LLC indicate a highly organized, likely North Korean state-sponsored operation. #graphalgo #NorthKorea
www.hendryadrian.com
April 10, 2026 at 12:45 AM
Researchers found Go malware delivered through 2 Go Modules and 2 Terraform providers, the first known abuse of HashiCorp's registry as a malware channel, tied to North Korea-linked campaigns. #HashiCorp #Terraform #NorthKorea
Attackers Use Malicious Terraform Providers To Deliver Go Malware Via HashiCorp Registry
Researchers uncovered Go-based malware distributed through two Go Modules and two Terraform providers, marking the first known abuse of HashiCorp’s centralized repository as a malware delivery channel. The activity overlaps with Graphalgo and other North Korea-linked campaigns that use fake job offers, npm, PyPI, Slack, and blockchain-based command channels to target...
www.hendryadrian.com
September 23, 2026 at 11:00 PM
A fake recruiter campaign, dubbed 'Graphalgo' and attributed to North Korean threat actors like the Lazarus group, is targeting JavaScript and Python developers by hiding malware in coding challenges.

www.bleepingcomputer.com/news/securit...
Fake job recruiters hide malware in developer coding challenges
A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks.
www.bleepingcomputer.com
February 27, 2026 at 12:24 PM