{"id":30413,"date":"2026-07-08T06:21:56","date_gmt":"2026-07-08T05:21:56","guid":{"rendered":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png"},"modified":"2026-07-08T06:26:50","modified_gmt":"2026-07-08T05:26:50","slug":"11-base32-decoded-payload-revealing-aws-credentials-after-executing-the-malicious-terraform-binary","status":"inherit","type":"attachment","link":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/ci-cd-security-supply-chain-attack-from-a-compromised-developer\/11-base32-decoded-payload-revealing-aws-credentials-after-executing-the-malicious-terraform-binary\/","title":{"rendered":"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary"},"author":1544,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"_acf_changed":false},"class_list":["post-30413","attachment","type-attachment","status-inherit","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary - RiskInsight<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary - RiskInsight\" \/>\n<meta property=\"og:description\" content=\"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png\" \/>\n<meta property=\"og:site_name\" content=\"RiskInsight\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-08T05:26:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png\" \/>\n\t<meta property=\"og:image:width\" content=\"911\" \/>\n\t<meta property=\"og:image:height\" content=\"494\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ma\u00eblie Lebaron\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png\",\"url\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png\",\"name\":\"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary - RiskInsight\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/#website\"},\"datePublished\":\"2026-07-08T05:21:56+00:00\",\"dateModified\":\"2026-07-08T05:26:50+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CI\\\/CD Security: Supply chain attack from a compromised developer\",\"item\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/2026\\\/07\\\/ci-cd-security-supply-chain-attack-from-a-compromised-developer\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/\",\"name\":\"RiskInsight\",\"description\":\"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/#organization\",\"name\":\"Wavestone\",\"url\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"contentUrl\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"width\":50,\"height\":50,\"caption\":\"Wavestone\"},\"image\":{\"@id\":\"https:\\\/\\\/www.riskinsight-wavestone.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary - RiskInsight","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png","og_locale":"en_US","og_type":"article","og_title":"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary - RiskInsight","og_description":"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary","og_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png","og_site_name":"RiskInsight","article_modified_time":"2026-07-08T05:26:50+00:00","og_image":[{"width":911,"height":494,"url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png","type":"image\/png"}],"twitter_misc":{"Written by":"Ma\u00eblie Lebaron"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png","name":"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary - RiskInsight","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website"},"datePublished":"2026-07-08T05:21:56+00:00","dateModified":"2026-07-08T05:26:50+00:00","breadcrumb":{"@id":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.riskinsight-wavestone.com\/en\/"},{"@type":"ListItem","position":2,"name":"CI\/CD Security: Supply chain attack from a compromised developer","item":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/07\/ci-cd-security-supply-chain-attack-from-a-compromised-developer\/"},{"@type":"ListItem","position":3,"name":"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary"}]},{"@type":"WebSite","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","name":"RiskInsight","description":"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants","publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization","name":"Wavestone","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","width":50,"height":50,"caption":"Wavestone"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/"}}]}},"description":{"rendered":"<p class=\"attachment\"><a href='https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png'><img loading=\"lazy\" decoding=\"async\" width=\"352\" height=\"191\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-352x191.png\" class=\"attachment-medium size-medium\" alt=\"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-352x191.png 352w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-71x39.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-768x416.png 768w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png 911w\" sizes=\"auto, (max-width: 352px) 100vw, 352px\" \/><\/a><\/p>\n"},"caption":{"rendered":"<p>Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary<\/p>\n"},"alt_text":"Base32-decoded payload revealing AWS credentials after executing the malicious Terraform binary","media_type":"image","mime_type":"image\/png","media_details":{"width":911,"height":494,"file":"2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png","filesize":386365,"sizes":{"medium":{"file":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-352x191.png","width":352,"height":191,"filesize":73953,"mime_type":"image\/png","source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-352x191.png"},"large":{"file":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-71x39.png","width":71,"height":39,"filesize":3883,"mime_type":"image\/png","source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-71x39.png"},"thumbnail":{"file":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-120x70.png","width":120,"height":70,"filesize":10039,"mime_type":"image\/png","source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-120x70.png"},"medium_large":{"file":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-768x416.png","width":768,"height":416,"filesize":295392,"mime_type":"image\/png","source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-768x416.png"},"gucherry-blog-thumbnail-one":{"file":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-800x450.png","width":800,"height":450,"filesize":313038,"mime_type":"image\/png","source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-800x450.png"},"gucherry-blog-thumbnail-two":{"file":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-300x300.png","width":300,"height":300,"filesize":89919,"mime_type":"image\/png","source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-300x300.png"},"gucherry-blog-thumbnail-three":{"file":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-800x400.png","width":800,"height":400,"filesize":284953,"mime_type":"image\/png","source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-800x400.png"},"gucherry-blog-thumbnail-four":{"file":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-600x450.png","width":600,"height":450,"filesize":229225,"mime_type":"image\/png","source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary-600x450.png"},"full":{"file":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png","width":911,"height":494,"mime_type":"image\/png","source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png"}},"image_meta":{"aperture":"0","credit":"","camera":"","caption":"","created_timestamp":"0","copyright":"","focal_length":"0","iso":"0","shutter_speed":"0","title":"","orientation":"0","keywords":[]}},"post":30390,"source_url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/07\/11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png","filename":"11-Base32-decoded-payload-revealing-AWS-credentials-after-executing-the-malicious-Terraform-binary.png","filesize":386365,"_links":{"self":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media\/30413","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media"}],"about":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/types\/attachment"}],"author":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/users\/1544"}],"replies":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/comments?post=30413"}],"wp:attached-to":[{"embeddable":true,"post_type":"post","id":30390,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/30390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}