Graphalgo malware has expanded into the Go ecosystem through malicious Terraform providers and Go Modules. The campaign involves gocommunity-io/dockerd, kreuzwenker/docker, gocommunity.io/orderedbtree, and gogets.dev/btreex, with the latter Terraform provider impersonating the legitimate kreuzwerker/docker package. The activity represents a targeted software supply-chain threat against developers and DevOps environments.
The malicious Terraform providers contain hidden execution paths that activate only when specific containerName and networkID values produce a predefined SHA256 hash. The resulting key decrypts an embedded archive whose files are subsequently executed as Go code. The Go module variants use similar techniques, including plaintext malware and payloads concealed inside files disguised as SQL content. A second-stage Go RAT collects system information such as the operating system, architecture, hostname, username, home directory, and Node.js availability. It uses encrypted Slack communications and an Ethereum smart contract as dual command-and-control channels, polling both sources for commands that can execute additional Go or JavaScript code or remove itself.[/subscribe_to_unlock_form]
Graphalgo malware has expanded into the Go ecosystem through malicious Terraform providers and Go Modules. The campaign involves gocommunity-io/dockerd, kreuzwenker/docker, gocommunity.io/orderedbtree, and gogets.dev/btreex, with the latter Terraform provider impersonating the legitimate kreuzwerker/docker package. The activity represents a targeted software supply-chain threat against developers and DevOps environments.
The malicious Terraform providers contain hidden execution paths that activate only when specific containerName and networkID values produce a predefined SHA256 hash. The resulting key decrypts an embedded archive whose files are subsequently executed as Go code. The Go module variants use similar techniques, including plaintext malware and payloads concealed inside files disguised as SQL content. A second-stage Go RAT collects system information such as the operating system, architecture, hostname, username, home directory, and Node.js availability. It uses encrypted Slack communications and an Ethereum smart contract as dual command-and-control channels, polling both sources for commands that can execute additional Go or JavaScript code or remove itself.[emaillocker id="1283"]
The campaign demonstrates continued abuse of developer ecosystems to deliver malware through trusted package mechanisms. Fake Go ecosystem websites and forged repository commits are also used to increase package credibility and obscure the malware's history. Organizations should review Terraform providers and Go dependencies for the identified packages, investigate affected developer machines or CI/CD runners, rotate exposed credentials, review infrastructure activity, isolate compromised systems, and reimage affected hosts where necessary.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1195 | Supply Chain Compromise | - |
| Initial access | T1195.001 | Supply Chain Compromise | Compromise Software Dependencies and Development Tools |
| Initial access | T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1573.001 | Encrypted Channel | Symmetric Cryptography |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Discovery | E1082 | System Information Discovery |
| Exfiltration | E1020 | Automated Exfiltration |
| Execution | E1204 | User Execution |
| Cryptography Micro-objective | C0031 | Decrypt Data |
| Defense Evasion | B0029 | Polymorphic Code |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Discovery | E1083 | File and Directory Discovery |
The following reports contain further technical details:
[/emaillocker]