Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

TraderTraitor's trojanized Terraform provider runs its malware loader the moment Terraform loads it

Zscaler ThreatLabz says North Korea's TraderTraitor hid a malware loader inside a fake HashiCorp Terraform provider that runs the moment Terraform loads it. The crypto-theft group has pushed its operation into infrastructure-as-code, the tooling that provisions cloud environments.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying TraderTraitor's trojanized Terraform provider runs its malware loader the moment Terraform loads it
Generated illustration

What happened

  • The malicious binary is written in Go, named terraform-provider-awsbeta_v1.0.0, and poses as an Amazon Web Services provider for HashiCorp Terraform.
  • The loader fingerprints the operating system and CPU architecture, then downloads a payload built for macOS, Linux or Windows.
  • Those payloads arrive as encrypted blobs appended to decoy .woff font files, recovered by marker-based extraction and AES-256-CBC decryption.
  • FLATROOF's Python stealers take browser credentials, cookies, terminal history, system information and cryptocurrency wallet extensions.
  • ROOFDECK finds its command server through local configuration, a cryptographically signed Pastebin dead drop and Nostr profile metadata.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Because the binaries run inside CI/CD and on engineers' workstations, one compromised plugin reaches the build pipeline as well as the engineer's machine.
  • capability Running a mix of macOS, Linux and Windows buys a team no safety here, since the plugin ships a payload for whichever OS the engineer runs.
  • precedent A trusted provider plugin has now been turned into a malware dropper, so IaC tooling joins the supply-chain attack surface defenders have to cover.

Terraform loads a provider as an executable plugin and runs it on the machine that invoked it [7]. Zscaler found that the author kept a functioning AWS provider scaffold and added a malicious sibling package named awsbeta, calling its routine directly from main [8]. The provider still behaves normally [9].

On first run the code looks for a file named session.lock in the temporary directory. If it is missing, the code downloads a second stage over HTTPS, writes a Bash script called safari_updater, marks it executable, launches it through sh -c as a detached child, and writes the lock so it will not run again [14]. The download points at hashicorp-terraform[.]io, a lookalike of HashiCorp's domain, on a path that imitates a legitimate Terraform plugin metrics endpoint [15].

FLATROOF is a Rust backdoor; once its stealers finish, it drops ROOFDECK for full remote control [10][12]. Zscaler links the activity to the earlier KelpDAO incident, which involved the same two malware families, and attributes it to TraderTraitor, also tracked as UNC4899, Jade Sleet and Slow Pisces [17][1][2]. SentinelLabs reported related TraderTraitor Terraform activity while Zscaler was preparing its writeup, covering the social engineering and intrusion while Zscaler took the provider internals and payload delivery [18].

Zscaler says it could not determine how the poisoned provider reached its victims [16]. The provider deserves the same handling as any package dependency, a pinned version and a verified source [7].

What to watch

  • Whether other registry-hosted Terraform or OpenTofu providers carry the same awsbeta-style sibling-package implant.
  • How the trojanized provider reached victims, which Zscaler could not establish.
  • Whether CI/CD platforms add provenance or signature verification to Terraform provider loads.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    In July 2026, Zscaler ThreatLabz uncovered a campaign linked to TraderTraitor, an advanced persistent threat actor backed by the North Korean government that has targeted the cryptocurrency industry for years.

    ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source
  2. [2]

    TraderTraitor is also tracked as Jade Sleet, UNC4899, Pressure Chollima and Slow Pisces.

    ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source
  3. [3]

    ThreatLabz discovered a trojanized Terraform provider that executes malicious code as soon as Terraform loads the provider.

    ReportedSupportedSource: Zscaler ThreatLabz2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. zscaler.com

    1 article · October 8, 2026

    Suspected TraderTraitor Group Uses Trojanized Terraform Provider to Deliver Cross-Platform Malware

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories