Critical Vulnerability in Terraform Exposes Developer Systems to Malware
Key Takeaways A new supply-chain attack leverages a trojanized Terraform provider to distribute cross-platform malware. Developer systems and CI/CD environments are at high risk, potentially exposing...
Key Takeaways
- A new supply-chain attack leverages a trojanized Terraform provider to distribute cross-platform malware.
- Developer systems and CI/CD environments are at high risk, potentially exposing sensitive credentials and source code.
- The campaign deploys sophisticated malware, including FLATROOF and ROOFDECK backdoors, targeting Windows, macOS, and Linux.
- The threat actor’s tactics resemble those of the suspected TraderTraitor group, though attribution remains unconfirmed.
- Immediate action is required for cloud engineers and DevOps teams to mitigate exposure and implement robust security practices.
A sophisticated supply-chain attack is actively exploiting Terraform provider workflows to infect developer systems across macOS, Linux, and Windows platforms with multi-stage malware. This campaign represents a significant threat to organizations relying on Terraform for infrastructure as code (IaC) deployments.
Table Of Content
The attack leverages a seemingly legitimate AWS-related plugin, which, unbeknownst to the user, has been weaponized to execute malicious code. This covert operation allows the malware to integrate seamlessly into standard development processes, making detection challenging.
This campaign poses an elevated risk to cloud engineers, DevOps teams, and developers working in cryptocurrency or Web3 environments. Terraform providers often execute on workstations and CI/CD systems that house critical assets such as source code repositories, cloud credentials, API keys, deployment permissions, and browser-stored login data, making them prime targets for data exfiltration and broader network compromise.
This incident echoes previous reports concerning deceptive Terraform job tests utilized to compromise developers through seemingly trustworthy infrastructure projects. For further details, a comprehensive analysis is available in the Hackers Abuse Trusted Terraform Workflows to Infect Developer Systems With Cross-Platform Malware report.
Researchers from Zscaler ThreatLabz identified this malware campaign in July 2026. While the tactics and targeting patterns bear resemblances to the activity of the suspected TraderTraitor group (also known as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces), Zscaler has stated that insufficient unique code, infrastructure, or cryptographic evidence prevents a high-confidence attribution to this specific threat actor.
The initial malicious file, named terraform-provider-awsbeta_v1.0.0, is written in Go and masquerades as an Amazon Web Services provider for HashiCorp Terraform. It integrates a functional provider structure to maintain an appearance of legitimacy. Crucially, an additional malicious package is embedded within, designed to execute immediately upon Terraform loading the provider.
Hackers Abuse Trusted Terraform Workflows
The rogue provider first checks for the presence of a session.lock file within the temporary directory. If this file is absent, it proceeds to download a Bash loader, which then runs in the background. Following successful execution, the lock file is created to prevent subsequent re-execution of the loader.
The Bash loader, dubbed safari_updater, is designed to be cross-platform aware. It assesses the operating system and CPU architecture of the compromised system to deliver a precisely tailored payload. This loader supports macOS, Linux, and Windows systems equipped with compatible Unix-like shells, including Cygwin, MinGW, or MSYS environments.
To evade detection, the loader downloads its payloads disguised as standard web-font files with the .woff extension. This technique is intended to make the payloads appear less suspicious during a cursory file inspection.

These malicious files contain legitimate decoy font content, followed by an @@ENDFONT@@ marker and an encrypted executable. The loader’s function is to extract this hidden data, Base64-decode it, and then decrypt it using AES-256-CBC. It intelligently selects the appropriate decryption tool from Python, Node.js, Perl, or OpenSSL, depending on what is available on the victim’s machine. On macOS, an additional step involves removing the quarantine attribute and applying an ad hoc code signature to bypass Gatekeeper warnings and facilitate execution.
The primary malware delivered in this campaign is FLATROOF, a backdoor written in Rust that boasts compatibility across all three major desktop operating systems. FLATROOF establishes persistence through various mechanisms: a Linux service, macOS logout configurations, or a Windows Registry Run value.
FLATROOF & ROOFDECK
FLATROOF is equipped with extensive capabilities, including system information gathering, process listing, file management, command execution, the ability to download subsequent payloads, exfiltration of stolen data, and self-removal functionality.
Its Python-based data stealers are particularly adept at targeting browser data from Chromium and Firefox. This includes extracting saved credentials, cookies, browsing history, autofill information, shell history, a list of installed applications, running processes, and the current username. On macOS, it extends its reach to collect Safari data and the login.keychain-db file. For Windows systems, the malware specifically targets Chrome, Edge, Brave, Windows Credential Manager entries, command history, and cryptocurrency wallet extension data from MetaMask, Phantom, Trust Wallet, and Rabby.
This concentrated focus on browser and wallet data aligns with an increasing trend of supply-chain threats against developer packages, particularly those targeting Web3 environments. Furthermore, the campaign deploys ROOFDECK, another backdoor designed for Windows and macOS, which offers more advanced remote-control functionalities.

ROOFDECK’s capabilities include file and disk discovery, remote shell command execution, file transfer operations, reading and writing clipboard data, managing background tasks, self-updating, and forensic trace erasure.
Its command-and-control (C2) discovery mechanism is particularly sophisticated, leveraging a local configuration file, a cryptographically signed Pastebin record, or Nostr profile metadata to locate its active server. This innovative use of public platforms for flexible delivery and control layers mirrors other advanced malware server hiding techniques observed in developer-focused campaigns.
What You Should Do
- Implement Provider Verification: Mandate strict verification for all Terraform providers. Restrict the use of unapproved providers and validate checksums in Terraform lock files.
- Review Provider Source Addresses: Scrutinize provider source addresses and actively block any lookalike domains that could be used for impersonation.
- Monitor for Anomalous Activity: Watch for Terraform-related processes initiating unexpected shell commands, the appearance of suspicious files in temporary directories, unusual
.wofffile downloads, and executables running from user profile folders. - Enhance CI/CD Security: Apply robust secure CI/CD pipeline practices. This includes mandatory code reviews, stringent dependency controls, secure secret management, and automated security scanning prior to any infrastructure changes being deployed.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-1 | 9d78ece09457907b730d139e4e0c64dd |
terraform-provider-awsbeta_v1.0.0 trojanized Terraform provider |
| SHA-1 | 73adaea97f003735335505858c1c6def |
safari_updater Bash loader |
| SHA-1 | 116f7189ed7b41f1b339a749d56e63be |
HiraginoSans-Bold.woff, encrypted macOS x86_64 FLATROOF |
| SHA-1 | be60c52ca8a01fef7dc15c2f0ebb77d8 |
HiraginoSans-Regular.woff, encrypted macOS ARM64 FLATROOF |
| SHA-1 | 58fa0d651898446d5f5d2ed8a27a3330 |
MalgunGothic-Bold.woff, encrypted Windows PE32+ FLATROOF |
| SHA-1 | 2621753691be9521288664bb551dfba6 |
MalgunGothic-Italic.woff, encrypted Windows PE32 FLATROOF |
| SHA-1 | ad0b1b6d2c8b9d09d6473a4a299470ab |
NotoSansCJK-Bold.woff, encrypted Linux x86-64 FLATROOF |
| SHA-1 | 4b8509cde757b5428e5f99c8dffe73ca |
NotoSansCJK-ExtraBold.woff, encrypted Linux ARM FLATROOF |
| SHA-1 | 3826dc7a9ba8bd5b1c143560c1530d89 |
NotoSansCJK-Italic.woff, encrypted Linux x86 FLATROOF |
| SHA-1 | 34a52e6a4d803e94fe497bab682abfd3 |
NotoSansCJK-Regular.woff, encrypted Linux ARM64 FLATROOF |
| SHA-1 | 2b81aceab0142472d94eb42e500b27b1 |
imagent |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.