A threat actor has distributed a Go implementation of the Graphalgo malware through two malicious Terraform providers and two Go modules—the first reported systematic abuse of Terraform providers for malware delivery. The packages used trigger-gated, encrypted payloads to selectively infect victims, then installed a second-stage Go remote-access trojan on Windows, Linux, and macOS systems. The RAT communicated through encrypted Slack infrastructure and the Arbitrum Sepolia blockchain; shared public-key, Slack, and blockchain infrastructure links the activity to the earlier Graphalgo npm campaign.
The operators also established fake Go-package ecosystems, including gocommunity.io and gogets.dev, to make the malicious modules appear legitimate and target Go developers and DevOps staff. The expansion follows prior Graphalgo activity using fake recruiter-test lures and coincides with the separate "Equation of Compromise" npm operation targeting DeFi and quantitative developers through trigger-activated packages and Sepolia-based command-and-control. Both campaigns demonstrate continued supply-chain targeting using conditional execution, encrypted multistage payloads, and blockchain-backed C2, although the available reporting does not establish that they are operated by the same actor.

Trace attribution and downstream blast radius.
8 events from the most recent confirmed update back to the earliest known activity.
JFrog Security Research published its analysis of Equation of Compromise, describing trigger-gated payload decryption, Ethereum Sepolia C2 contracts, Slack-based tasking, and GitHub Actions download-farming infrastructure.
The threat actor published gogets.dev/btreex, concealing its malware in a ZIP archive masquerading as btreex.sql. Forged repository commits were used to make Go module services show a falsified November 2025 release date.
The threat actor published gocommunity.io/orderedbtree, a Go module containing the malware in plaintext.
The Arbitrum Sepolia smart contract used for Graphalgo-linked blockchain command and control began receiving transactions on August 6, 2026.
The qa-announcements channel in the Portfolio-testers Slack workspace accumulated encrypted Graphalgo-related C2 messages beginning July 16, 2026.
A public key later associated with the Graphalgo-linked Go and Terraform malware was present in malicious NPM payloads beginning with the modern-events package.
The Equation of Compromise npm supply-chain campaign reportedly became active in March 2026, targeting quantitative-development and DeFi users through malicious packages including mathsbase.
A threat actor distributed a Go-based Graphalgo-linked malware through the malicious Terraform providers gocommunity-io/dockerd and typosquatted kreuzwenker/docker, as well as the gocommunity.io/orderedbtree and gogets.dev/btreex Go modules. The trigger-gated payload deployed a Go RAT using encrypted Slack and Arbitrum Sepolia blockchain command-and-control channels.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
aikido.dev
Open sourcecyberveille.ch
Open sourcereversinglabs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.