Zscaler ThreatLabz said on 8 October 2026 that it found, in July 2026, a fake Terraform plugin carrying malware. Terraform is cloud-setup software, and its plugins run as programs on the user's machine. This one posed as an Amazon Web Services provider. The attackers added their own code to a working provider, so it runs as soon as Terraform starts it. It fetches a script from a lookalike domain, and the script picks malware for the victim's system. The malware, FLATROOF, steals browser data, then installs a remote-control tool, ROOFDECK.
Zscaler sees strong overlap with TraderTraitor, a North Korea-backed group. It has not found unique code similarities, shared infrastructure or cryptographic links. Those are not strong enough to attribute the campaign to the group on its own with high confidence. FLATROOF and ROOFDECK were also reported in the earlier KelpDAO incident. It is unclear how the plugin reached the victim.
A provider is trusted code that runs with the engineer's access, and this one kept working while it attacked. Zscaler advises limiting untrusted providers, checking checksums and monitoring for unexpected process activity.