VMTech
Discuss a project

Jade Sleet tied to Indian IT provider compromise on macOS

Jade Sleet tied to Indian IT provider compromise on macOS

SentinelOne has linked the North Korean threat actor Jade Sleet to the compromise of an India-based IT services provider after finding the FLATROOF and ROOFDECK backdoors on an Apple Silicon MacBook used by a DevOps engineer. The malware was present on the endpoint as early as March 18, 2026, while beaconing and host activity began on March 29.

The incident shows the group’s continued focus on developers and the systems they use to manage infrastructure. Jade Sleet is also known as PUKCHONG, Slow Pisces, TraderTraitor and UNC4899. It has a record of targeting cryptocurrency and blockchain organisations as well as vendors serving those businesses.

Backdoors found on a developer endpoint

SentinelOne said the implants were first launched by Cursor on March 29, seconds after the cloudshield workspace in a DevOps-Automation directory was opened. The exact delivery mechanism in this case remains unknown. The researchers assess that ROOFDECK is typically deployed after attackers have already established an initial foothold and control of a host.

An updated ROOFDECK build was deployed to the engineer’s system on April 20, one day after LayerZero publicly acknowledged the KelpDAO hack. That version removed existing ROOFDECK and FLATROOF binaries and stripped symbols and debug information, measures intended to make detection more difficult.

Terraform lures create a supply-chain entry point

The campaign uses social engineering in the form of purported job interviews, directing job seekers to coding-project repositories themed around the infrastructure work of the company being impersonated. SentinelOne observed names including gtn-candidate-repo, Northwind-IAC, novacart-interview and terraform-candidate-repo.

These repositories contain a weaponised .terraform.lock.hcl dependency lock file. When an unsuspecting developer runs terraform init, the file can direct the platform to malicious domains such as registry.hashicorp-aws[.]com and trigger downloads of attacker-controlled modules. The lures have targeted people working in DevOps, cryptocurrency and financial technology roles.

FLATROOF and ROOFDECK capabilities

Both malware families are written in Rust and target ARM-based macOS systems. FLATROOF, also called Gaslight, uses Telegram for command-and-control. It can execute commands, upload and download files, and collect data through a Python module. The collection includes Chrome, Brave, Firefox and Safari data, Terminal command histories, installed applications, hardware and software profiles, running processes and a copy of login.keychain-db.

ROOFDECK uses the decentralised Nostr protocol for command-and-control. Its functions include reconnaissance, file manipulation, remote shell access, lateral movement and persistence through Launch Agents. SentinelOne said its commands are signed with an operator private key and verified against an embedded public key before execution; its code also re-implements common directory and file shell commands.

Business implication

Developer endpoints can hold access to cloud environments, source code and delivery pipelines, making them an attractive route into larger targets. Organisations should treat interview repositories and infrastructure-as-code dependencies as untrusted until reviewed, and prioritise monitoring and protection for development devices that can reach cloud credentials, pipelines and production-adjacent systems.

#cybersecurity#macossecurity#supplychain#devops
Open analytics
On the site 0 views
min read 4 21.09.2026
Instagram

Jade Sleet tied to Indian IT provider compromise on macOS

Open the post on Instagram ↗