Skip to content
Brief Security & Trust ·

Fake Terraform plugin used to plant malware on developer machines

Zscaler says the campaign looks like North Korea-linked TraderTraitor, but it cannot confirm that.

In brief
  • Zscaler ThreatLabz found a fake Terraform AWS plugin that still works normally while it installs malware. The malware steals browser data and gives attackers remote control.
  • Zscaler sees strong overlap with TraderTraitor but cannot confirm the link with high confidence. It is not clear how the plugin reached victims.

Zscaler ThreatLabz said on 8 October 2026 that it found, in July 2026, a fake Terraform plugin carrying malware. Terraform is cloud-setup software, and its plugins run as programs on the user's machine. This one posed as an Amazon Web Services provider. The attackers added their own code to a working provider, so it runs as soon as Terraform starts it. It fetches a script from a lookalike domain, and the script picks malware for the victim's system. The malware, FLATROOF, steals browser data, then installs a remote-control tool, ROOFDECK.

Zscaler sees strong overlap with TraderTraitor, a North Korea-backed group. It has not found unique code similarities, shared infrastructure or cryptographic links. Those are not strong enough to attribute the campaign to the group on its own with high confidence. FLATROOF and ROOFDECK were also reported in the earlier KelpDAO incident. It is unclear how the plugin reached the victim.

A provider is trusted code that runs with the engineer's access, and this one kept working while it attacked. Zscaler advises limiting untrusted providers, checking checksums and monitoring for unexpected process activity.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Zscaler ThreatLabz.