Graphalgo campaign spreads to Terraform providers and Go Modules
2026-09-22 • Aikido •
Graphalgo malware was distributed through two Terraform providers and two Go modules, using conditional activation to remain inert outside specially crafted runtime conditions. Its Go-based RAT collects host information and receives encrypted commands through Slack workspaces and an Ethereum smart contract on the Arbitrum Sepolia testnet. Shared infrastructure and cryptographic material connect the samples to earlier Graphalgo npm payloads, while fake Go ecosystem websites and forged Git commits were used to lend legitimacy to malicious packages. Aikido observed 18 unique hostnames in check-in data and assessed the operation as small and targeted.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| WALLET | 0xAD02b5cDE693529d3bdA026629950… | 2026-09-22 | 2026-09-22 |
| URL | https://mediumstar.slack.com | 2026-09-22 | 2026-09-22 |
| URL | https://portfolio-testers.slack… | 2026-09-22 | 2026-09-22 |
| URL | https://portfolio-devs.slack.com | 2026-09-22 | 2026-09-22 |
| DOMAIN | gogets.dev | 2026-09-22 | 2026-09-22 |
| DOMAIN | gocommunity.io | 2026-09-22 | 2026-09-22 |
| HASH | ab01686d87565250fc4989faddb877d… | 2026-09-22 | 2026-09-22 |
| HASH | 5f892a5424e88a21a3eb3d7f82ebf04… | 2026-09-22 | 2026-09-22 |