SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
TraderTraitor's trojanized Terraform provider runs its malware loader the moment Terraform loads it
Zscaler ThreatLabz says North Korea's TraderTraitor hid a malware loader inside a fake HashiCorp Terraform provider that runs the moment Terraform loads it. The crypto-theft group has pushed its operation into infrastructure-as-code, the tooling that provisions cloud environments.
The Watch · Security desk

What happened
- The malicious binary is written in Go, named terraform-provider-awsbeta_v1.0.0, and poses as an Amazon Web Services provider for HashiCorp Terraform.
- The loader fingerprints the operating system and CPU architecture, then downloads a payload built for macOS, Linux or Windows.
- Those payloads arrive as encrypted blobs appended to decoy .woff font files, recovered by marker-based extraction and AES-256-CBC decryption.
- FLATROOF's Python stealers take browser credentials, cookies, terminal history, system information and cryptocurrency wallet extensions.
- ROOFDECK finds its command server through local configuration, a cryptographically signed Pastebin dead drop and Nostr profile metadata.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Because the binaries run inside CI/CD and on engineers' workstations, one compromised plugin reaches the build pipeline as well as the engineer's machine.
- capability Running a mix of macOS, Linux and Windows buys a team no safety here, since the plugin ships a payload for whichever OS the engineer runs.
- precedent A trusted provider plugin has now been turned into a malware dropper, so IaC tooling joins the supply-chain attack surface defenders have to cover.
Terraform loads a provider as an executable plugin and runs it on the machine that invoked it [7]. Zscaler found that the author kept a functioning AWS provider scaffold and added a malicious sibling package named awsbeta, calling its routine directly from main [8]. The provider still behaves normally [9].
On first run the code looks for a file named session.lock in the temporary directory. If it is missing, the code downloads a second stage over HTTPS, writes a Bash script called safari_updater, marks it executable, launches it through sh -c as a detached child, and writes the lock so it will not run again [14]. The download points at hashicorp-terraform[.]io, a lookalike of HashiCorp's domain, on a path that imitates a legitimate Terraform plugin metrics endpoint [15].
FLATROOF is a Rust backdoor; once its stealers finish, it drops ROOFDECK for full remote control [10][12]. Zscaler links the activity to the earlier KelpDAO incident, which involved the same two malware families, and attributes it to TraderTraitor, also tracked as UNC4899, Jade Sleet and Slow Pisces [17][1][2]. SentinelLabs reported related TraderTraitor Terraform activity while Zscaler was preparing its writeup, covering the social engineering and intrusion while Zscaler took the provider internals and payload delivery [18].
Zscaler says it could not determine how the poisoned provider reached its victims [16]. The provider deserves the same handling as any package dependency, a pinned version and a verified source [7].
What to watch
- Whether other registry-hosted Terraform or OpenTofu providers carry the same awsbeta-style sibling-package implant.
- How the trojanized provider reached victims, which Zscaler could not establish.
- Whether CI/CD platforms add provenance or signature verification to Terraform provider loads.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
In July 2026, Zscaler ThreatLabz uncovered a campaign linked to TraderTraitor, an advanced persistent threat actor backed by the North Korean government that has targeted the cryptocurrency industry for years.
ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source - [2]
TraderTraitor is also tracked as Jade Sleet, UNC4899, Pressure Chollima and Slow Pisces.
ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source - [3]
ThreatLabz discovered a trojanized Terraform provider that executes malicious code as soon as Terraform loads the provider.
ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source - [4]
The loader selects payloads for macOS, Linux and Windows according to the operating system and CPU architecture.
ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source - [5]
Encrypted executables are appended to decoy .woff files and recovered using marker-based extraction and AES-256-CBC decryption.
ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source - [6]
The initial payload is written in Go and named terraform-provider-awsbeta_v1.0.0, masquerading as an Amazon Web Services provider for HashiCorp Terraform.
ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source - [7]
Terraform providers are executable plugins loaded by Terraform to communicate with infrastructure platforms and services.
ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source - [8]
The threat actor added a malicious sibling package named awsbeta to a functional provider scaffold and called its exported routine directly from main, so the malicious code executes when Terraform starts the provider.
ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source - [9]
The trojanized Terraform provider downloads a cross-platform Bash loader from a HashiCorp-themed lookalike domain while preserving normal Terraform behavior.
- [10]
The delivered FLATROOF variant is a Rust-based cross-platform backdoor with platform-specific persistence and redundant C2 channels.
- [11]
The FLATROOF Python stealers target browser credentials, cookies, terminal history, system information and cryptocurrency wallet extensions.
- [12]
FLATROOF deploys Python scripts to steal data from the victim before ultimately dropping the ROOFDECK backdoor to gain full remote control.
- [13]
The ROOFDECK backdoor uses layered C2 discovery through local configuration, a cryptographically signed Pastebin dead drop and Nostr profile metadata.
- [14]
The provider uses a session.lock file in the temporary directory as a run-once marker; if it is absent the provider downloads a second stage over HTTPS, writes a Bash payload named safari_updater, makes it executable, launches it through sh -c as a detached child, and creates the lock file to prevent repeated execution.
- [15]
The download URL uses the lookalike domain hashicorp-terraform[.]io and a path resembling a legitimate Terraform plugin metrics endpoint.
- [16]
It remains unclear how the trojanized Terraform provider was delivered to the victim.
- [17]
The campaign significantly overlaps with the previously reported KelpDAO incident, whose analysis discussed both FLATROOF and ROOFDECK.
- [18]
While Zscaler was preparing its analysis, SentinelLabs independently reported related TraderTraitor activity involving weaponized Terraform projects, FLATROOF and ROOFDECK, focusing on the social engineering and initial intrusion while Zscaler focused on the provider's implementation and payload delivery.
- [19]
Terraform provider binaries execute on developer workstations and CI/CD systems, which suggests the campaign may target cloud engineers or developers who use Terraform.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Infrastructure-as-Code SecurityFollow
- Software Supply Chain AttacksFollow
- Cryptocurrency theftFollow
- North Korean Cyber OperationsFollow