New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic

A devastating new backdoor, dubbed “Ted”, has been discovered lurking within HAProxy builds, potentially leaving thousands of organizations vulnerable to interception and data theft. This stealthy malware is embedded deep within a victim’s own infrastructure, making it a ticking time bomb waiting to unleash chaos on unsuspecting networks.

HAProxy is an open-source load balancer used by many web applications to distribute incoming traffic efficiently. However, the latest version of HAProxy contains a vulnerability that allows attackers to inject malicious code into the software. This backdoor, codenamed “Ted”, enables hackers to intercept sensitive data in real-time, as it passes through the compromised HAProxy instance.

The process is both clever and insidious. An attacker can manipulate an organization’s build process or supply chain, injecting the Ted malware into the HAProxy code. Once embedded, the backdoor remains dormant until activated by the attacker, who can then siphon off sensitive information such as login credentials, financial data, or even intellectual property.

The scope of the affected organizations is vast and unsettling. Any company using HAProxy in its infrastructure could be at risk, regardless of industry or size. Given the widespread adoption of HAProxy, it’s likely that numerous high-profile companies have been compromised without their knowledge. Furthermore, since Ted operates by intercepting traffic within an organization’s own network, detection may prove challenging.

The discovery of Ted has significant implications for cybersecurity professionals. It highlights the importance of scrutinizing software supply chains and code integrity. Organizations must reassess their build processes to prevent similar vulnerabilities in the future. Moreover, this incident serves as a stark reminder that even seemingly secure technologies can harbor hidden threats.

To protect against such sophisticated attacks, we urge organizations to take immediate action: conduct thorough risk assessments of HAProxy instances, implement strict access controls, and regularly monitor for suspicious activity within their networks. Furthermore, companies should prioritize code signing and verification procedures to ensure the integrity of their software builds. By taking proactive steps, organizations can minimize the risk of falling victim to Ted and similar stealthy backdoors.


Source: The Hacker News — 2026-09-04