Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GhostAction Attack Steals Secrets from GitHub Repositories
October 9, 2026
Critical Vulnerability in Terraform Exposes Developer Systems to Malware
October 9, 2026
Cisco Talos: AI Autonomous Agents Could Transform Pentests Into Covert Red Team Operations
October 9, 2026
Home/CyberSecurity News/Critical Vulnerability in Terraform Exposes Developer Systems to Malware
CyberSecurity News

Critical Vulnerability in Terraform Exposes Developer Systems to Malware

Key Takeaways A new supply-chain attack leverages a trojanized Terraform provider to distribute cross-platform malware. Developer systems and CI/CD environments are at high risk, potentially exposing...

Marcus Rodriguez
Marcus Rodriguez
October 9, 2026 5 Min Read
2 0

Key Takeaways

  • A new supply-chain attack leverages a trojanized Terraform provider to distribute cross-platform malware.
  • Developer systems and CI/CD environments are at high risk, potentially exposing sensitive credentials and source code.
  • The campaign deploys sophisticated malware, including FLATROOF and ROOFDECK backdoors, targeting Windows, macOS, and Linux.
  • The threat actor’s tactics resemble those of the suspected TraderTraitor group, though attribution remains unconfirmed.
  • Immediate action is required for cloud engineers and DevOps teams to mitigate exposure and implement robust security practices.

A sophisticated supply-chain attack is actively exploiting Terraform provider workflows to infect developer systems across macOS, Linux, and Windows platforms with multi-stage malware. This campaign represents a significant threat to organizations relying on Terraform for infrastructure as code (IaC) deployments.

Table Of Content

  • Key Takeaways
  • Hackers Abuse Trusted Terraform Workflows
  • FLATROOF & ROOFDECK
  • What You Should Do

The attack leverages a seemingly legitimate AWS-related plugin, which, unbeknownst to the user, has been weaponized to execute malicious code. This covert operation allows the malware to integrate seamlessly into standard development processes, making detection challenging.

This campaign poses an elevated risk to cloud engineers, DevOps teams, and developers working in cryptocurrency or Web3 environments. Terraform providers often execute on workstations and CI/CD systems that house critical assets such as source code repositories, cloud credentials, API keys, deployment permissions, and browser-stored login data, making them prime targets for data exfiltration and broader network compromise.

This incident echoes previous reports concerning deceptive Terraform job tests utilized to compromise developers through seemingly trustworthy infrastructure projects. For further details, a comprehensive analysis is available in the Hackers Abuse Trusted Terraform Workflows to Infect Developer Systems With Cross-Platform Malware report.

Researchers from Zscaler ThreatLabz identified this malware campaign in July 2026. While the tactics and targeting patterns bear resemblances to the activity of the suspected TraderTraitor group (also known as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces), Zscaler has stated that insufficient unique code, infrastructure, or cryptographic evidence prevents a high-confidence attribution to this specific threat actor.

The initial malicious file, named terraform-provider-awsbeta_v1.0.0, is written in Go and masquerades as an Amazon Web Services provider for HashiCorp Terraform. It integrates a functional provider structure to maintain an appearance of legitimacy. Crucially, an additional malicious package is embedded within, designed to execute immediately upon Terraform loading the provider.

Hackers Abuse Trusted Terraform Workflows

The rogue provider first checks for the presence of a session.lock file within the temporary directory. If this file is absent, it proceeds to download a Bash loader, which then runs in the background. Following successful execution, the lock file is created to prevent subsequent re-execution of the loader.

The Bash loader, dubbed safari_updater, is designed to be cross-platform aware. It assesses the operating system and CPU architecture of the compromised system to deliver a precisely tailored payload. This loader supports macOS, Linux, and Windows systems equipped with compatible Unix-like shells, including Cygwin, MinGW, or MSYS environments.

To evade detection, the loader downloads its payloads disguised as standard web-font files with the .woff extension. This technique is intended to make the payloads appear less suspicious during a cursory file inspection.

Infection chain (Source - Zscaler)
Infection chain (Source – Zscaler)

These malicious files contain legitimate decoy font content, followed by an @@ENDFONT@@ marker and an encrypted executable. The loader’s function is to extract this hidden data, Base64-decode it, and then decrypt it using AES-256-CBC. It intelligently selects the appropriate decryption tool from Python, Node.js, Perl, or OpenSSL, depending on what is available on the victim’s machine. On macOS, an additional step involves removing the quarantine attribute and applying an ad hoc code signature to bypass Gatekeeper warnings and facilitate execution.

The primary malware delivered in this campaign is FLATROOF, a backdoor written in Rust that boasts compatibility across all three major desktop operating systems. FLATROOF establishes persistence through various mechanisms: a Linux service, macOS logout configurations, or a Windows Registry Run value.

FLATROOF & ROOFDECK

FLATROOF is equipped with extensive capabilities, including system information gathering, process listing, file management, command execution, the ability to download subsequent payloads, exfiltration of stolen data, and self-removal functionality.

Its Python-based data stealers are particularly adept at targeting browser data from Chromium and Firefox. This includes extracting saved credentials, cookies, browsing history, autofill information, shell history, a list of installed applications, running processes, and the current username. On macOS, it extends its reach to collect Safari data and the login.keychain-db file. For Windows systems, the malware specifically targets Chrome, Edge, Brave, Windows Credential Manager entries, command history, and cryptocurrency wallet extension data from MetaMask, Phantom, Trust Wallet, and Rabby.

This concentrated focus on browser and wallet data aligns with an increasing trend of supply-chain threats against developer packages, particularly those targeting Web3 environments. Furthermore, the campaign deploys ROOFDECK, another backdoor designed for Windows and macOS, which offers more advanced remote-control functionalities.

Attacker-controlled GitHub repository hosting encrypted payloads disguised as font files (Source - Zscaler)
Attacker-controlled GitHub repository hosting encrypted payloads disguised as font files (Source – Zscaler)

ROOFDECK’s capabilities include file and disk discovery, remote shell command execution, file transfer operations, reading and writing clipboard data, managing background tasks, self-updating, and forensic trace erasure.

Its command-and-control (C2) discovery mechanism is particularly sophisticated, leveraging a local configuration file, a cryptographically signed Pastebin record, or Nostr profile metadata to locate its active server. This innovative use of public platforms for flexible delivery and control layers mirrors other advanced malware server hiding techniques observed in developer-focused campaigns.

What You Should Do

  • Implement Provider Verification: Mandate strict verification for all Terraform providers. Restrict the use of unapproved providers and validate checksums in Terraform lock files.
  • Review Provider Source Addresses: Scrutinize provider source addresses and actively block any lookalike domains that could be used for impersonation.
  • Monitor for Anomalous Activity: Watch for Terraform-related processes initiating unexpected shell commands, the appearance of suspicious files in temporary directories, unusual .woff file downloads, and executables running from user profile folders.
  • Enhance CI/CD Security: Apply robust secure CI/CD pipeline practices. This includes mandatory code reviews, stringent dependency controls, secure secret management, and automated security scanning prior to any infrastructure changes being deployed.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-1 9d78ece09457907b730d139e4e0c64dd terraform-provider-awsbeta_v1.0.0 trojanized Terraform provider
SHA-1 73adaea97f003735335505858c1c6def safari_updater Bash loader
SHA-1 116f7189ed7b41f1b339a749d56e63be HiraginoSans-Bold.woff, encrypted macOS x86_64 FLATROOF
SHA-1 be60c52ca8a01fef7dc15c2f0ebb77d8 HiraginoSans-Regular.woff, encrypted macOS ARM64 FLATROOF
SHA-1 58fa0d651898446d5f5d2ed8a27a3330 MalgunGothic-Bold.woff, encrypted Windows PE32+ FLATROOF
SHA-1 2621753691be9521288664bb551dfba6 MalgunGothic-Italic.woff, encrypted Windows PE32 FLATROOF
SHA-1 ad0b1b6d2c8b9d09d6473a4a299470ab NotoSansCJK-Bold.woff, encrypted Linux x86-64 FLATROOF
SHA-1 4b8509cde757b5428e5f99c8dffe73ca NotoSansCJK-ExtraBold.woff, encrypted Linux ARM FLATROOF
SHA-1 3826dc7a9ba8bd5b1c143560c1530d89 NotoSansCJK-Italic.woff, encrypted Linux x86 FLATROOF
SHA-1 34a52e6a4d803e94fe497bab682abfd3 NotoSansCJK-Regular.woff, encrypted Linux ARM64 FLATROOF
SHA-1 2b81aceab0142472d94eb42e500b27b1 imagent

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Cisco Talos: AI Autonomous Agents Could Transform Pentests Into Covert Red Team Operations

Next Post

GhostAction Attack Steals Secrets from GitHub Repositories

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Warden Stealer Spreads Via Malvertising and Cracked Software
October 9, 2026
MATCHBOIL Malware Uses Cloudflare to Hide C2 Servers, Delivers Backdoor Payloads
October 9, 2026
Telegram Desktop Critical Flaw Lets Attackers Take Over Accounts
October 9, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us