CVE
Not assigned
CWE
CWE-506, CWE-829, CWE-522
Affected Surface
- Terraform users and Go developers who resolved gocommunity-io/dockerd, kreuzwenker/docker, gocommunity.io/orderedbtree, or gogets.dev/btreex during September 2026
- GitHub workflows that referenced actions-cool/issues-helper or actions-cool/maintain-one-comment by mutable tag after the repositories became reachable again on 16 September 2026
- Teams still investigating whether September package incidents reached developer workstations, CI runners, or infrastructure automation hosts with long-lived credentials
Welcome to Corgea’s weekly briefing. The briefing covers the most important security findings and research from the week.
This edition covers new reporting published between Monday, 22 September and Friday, 25 September 2026, while skipping incidents Corgea had already covered in the 22 September briefing and the separate 24 September MemTensor article.
Top Article
Graphalgo reached Terraform providers and Go modules with trigger-gated Go malware
The cleanest new package-registry story in this window is Aikido’s 22 September report on Graphalgo spreading into Terraform providers and Go modules. That is a more important supply-chain update than it may sound at first glance. Terraform and Go dependencies tend to land on machines that already hold cloud, registry, and deployment credentials, so the initial foothold is closer to production authority than a typical npm dev dependency.
The article also exposed a pattern defenders should keep in mind for future registry incidents. The live cleanup state already diverges by ecosystem. In this environment, the Terraform registry entries are gone, but the Go proxy still serves the malicious module names and still shows the forged 2025 date on gogets.dev/btreex. That means current package pages can make a real exposure window look older, smaller, or cleaner than it actually was.
For the code path, package names alone are not the story. The Go modules wait for a matching reflected price field, then decrypt a local working tree and detach into go run .. The Terraform providers used a different trigger, but the same idea: hide the execution path behind normal-looking provider behavior and only fire on specific runtime inputs. The full write-up is in Corgea’s new Graphalgo Terraform and Go modules article.
More news
Re-enabled Mini Shai-Hulud GitHub Actions reopened an old compromise
Socket’s 24 September report is the most important follow-up item from the week. Two GitHub Actions tied to the May Mini Shai-Hulud campaign, actions-cool/issues-helper and actions-cool/maintain-one-comment, became reachable again on 16 September with malicious tags still intact. Socket estimated about 15,000 dependent repositories for issues-helper alone.
The useful operational point is that no new compromise was needed. Workflows that referenced those actions by mutable tag resumed downloading and running the old payload as soon as GitHub made the repositories reachable again. Socket updated the post on 25 September to say both actions have since been disabled again, but any workflow that ran during the re-enabled window still deserves secret rotation and run-history review.
If you need the older campaign mechanics, start with Corgea’s earlier article on Mini Shai-Hulud and the TanStack compromise. The new Socket post is best read as a trust-boundary follow-up: containment that depends on an upstream platform switch can disappear without any change to your own workflow files.
Other news
- The requested scan of CISA KEV, NVD, Aikido, Wiz, Socket, Endor Labs, and broader web search did not produce a second stronger package-registry or Linux story from 22-25 September than the Graphalgo article and the already-covered MemTensor compromise. CISA’s fresh 24 September KEV entries centered on Adobe Commerce, WSO2, F5, and adjacent enterprise infrastructure rather than the package-manager or Linux developer-surface focus requested for this run.
- Aikido’s Graphalgo report also helps explain why Corgea’s 22 September mathmain coverage still matters. The package names changed, but the control plane pattern did not. Slack tasking, blockchain dead drops, trigger-gated payloads, and registry artifacts that diverge from source homepages remain the recurring theme.
- If you are scoping adjacent September exposure, the nearest carry-over remains the 24 September MemTensor article, especially for teams running AI-agent tooling on workstations or CI runners that also hold package-publishing or cloud credentials.
From research to remediation
Check whether this pattern exists in your codebase
Turn this research into a remediation workflow. Scan dependencies and package manifests for similar supply-chain risk, then prioritize fixes with reachability context.