VYPR
researchPublished Oct 9, 2026· 1 source

Hackers Abuse Terraform Workflows to Distribute Cross-Platform Malware

A sophisticated supply-chain attack is leveraging trojanized Terraform provider workflows to distribute cross-platform malware, targeting developer systems with tools designed for macOS, Linux, and Windows.

A new supply-chain campaign is exploiting the trust inherent in Terraform provider workflows to deliver cross-platform malware, infecting developer systems with tools capable of running on macOS, Linux, and Windows. The attack utilizes a trojanized Terraform provider, disguised as a legitimate AWS-related plugin, which allows it to execute malicious code while maintaining the appearance of normal functionality. This campaign poses a significant risk to cloud engineers, DevOps teams, and cryptocurrency developers, as compromised workstations and CI/CD systems often contain sensitive access credentials, API keys, and deployment permissions.

The campaign's methodology involves a malicious Go-written plugin named terraform-provider-awsbeta_v1.0.0. Once Terraform loads this provider, a hidden malicious package activates. It checks for a session.lock file in the temporary directory; if absent, it downloads and executes a Bash loader script named safari_updater. This loader then determines the victim's operating system and CPU architecture to select and download a tailored payload, often disguised as .woff web-font files to evade initial scrutiny.

The downloaded payloads are encrypted executables embedded within these decoy font files. The Bash loader extracts this hidden data, Base64-decodes it, and then decrypts it using AES-256-CBC. The decryption process can leverage various tools like Python, Node.js, Perl, or OpenSSL, depending on what is available on the compromised system. On macOS, additional steps are taken to remove the quarantine attribute and apply an ad hoc code signature, helping the malware bypass macOS Gatekeeper security warnings.

The primary malware identified is FLATROOF, a Rust-based backdoor designed for macOS, Linux, and Windows. It establishes persistence through methods such as creating a Linux service, a macOS logout configuration, or a Windows Registry Run key. FLATROOF is capable of collecting system information, managing files, executing commands remotely, downloading further payloads, exfiltrating stolen data, and self-removal.

Complementing FLATROOF, the campaign also deploys ROOFDECK, a backdoor specifically for Windows and macOS that offers more advanced remote control capabilities. ROOFDECK can discover files and disks, execute shell commands, transfer files, interact with the clipboard, manage background tasks, update itself, and clean up its tracks. Its command-and-control (C2) discovery mechanism is particularly noteworthy, utilizing local configuration files, signed Pastebin entries, or Nostr profile metadata to locate its active server, demonstrating a flexible approach to maintaining C2 communication.

Both FLATROOF and ROOFDECK are equipped with data-stealing modules. Their Python-based components target browser data from Chromium, Firefox, and Safari (on macOS), including saved credentials, cookies, browsing history, and autofill data. They also focus on cryptocurrency wallet data from popular extensions like MetaMask, Phantom, Trust Wallet, and Rabby, aligning with a growing trend of targeting Web3 developer environments. On Windows, they target Chrome, Edge, Brave, and Windows Credential Manager entries.

This incident underscores the critical need for robust provider verification within Terraform security practices. Security teams are advised to restrict the use of unapproved providers, validate checksums in Terraform lock files, scrutinize provider source addresses, and block lookalike domains. Monitoring for unusual Terraform process behavior, unexpected files in temporary directories, suspicious file downloads, and executables running from user profile folders are also crucial detection measures. Implementing secure CI/CD pipeline practices, including code review, dependency controls, secret management, and automated scanning, can further mitigate risks before infrastructure changes are deployed.

Researchers from Zscaler ThreatLabz identified this campaign in July 2026 and noted similarities to suspected TraderTraitor activity, though definitive attribution remains pending due to insufficient unique evidence. The campaign's targeting of developer tools and sensitive information highlights the evolving tactics of threat actors seeking to compromise software development lifecycles and gain access to valuable cloud infrastructure and data.

Synthesized by Vypr AI