Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-23 · updated: 2026-09-23 · tags: [incident, global, macos] · confidence: high · severity: low · affected_sectors: [global] · au_impact: true

Aikido has documented malware distributed through at least two Terraform providers and two Go modules — the first time it has observed malicious Terraform providers — as the Graphalgo campaign moves beyond the npm ecosystem where ReversingLabs first reported it in February 2026. The packages are gocommunity-io/dockerd and kreuzwenker/docker (a typosquat of the legitimate kreuzwerker/docker provider, which reports 56 million downloads), and the Go modules gocommunity.io/orderedbtree and gogets.dev/btreex; OpenSourceMalware verified both Go modules on 22 September and archived them as part of today's 24 new records, noting the attacker stood up at least two fake Go package-ecosystem websites (gocommunity[.]io, gogets[.]dev) to lend them legitimacy. The payload is inert unless the SHA256 hash of specific runtime inputs equals b9966e37…8ad5, which then serves as an AES key to decrypt an embedded archive and run it through a detached go run; the second stage is a Go RAT with dual C2 — system reconnaissance posted in plaintext to a frontend-devs Slack channel before encrypted traffic moves to a second workspace, and commands polled every three seconds from an Ethereum smart contract on the Arbitrum Sepolia testnet. Both channels share the actor's public key with earlier npm samples, and OSM records 18 unique victim hostnames across Windows, Linux and macOS, which is consistent with a small, targeted operation rather than a broad campaign.

Attribute Detail
Sector Global (Macro)
Date 2026-09-23
Source Aikido
Reliability Tier 2