Jade Sleet Profile: Backdoor macOS turns DevOps into gateway to cloud infrastructure

Jade Sleet, a North Korea-linked threat group also tracked under the names TraderTraitor, UNC4899 and PUKCHONG, has expanded its operations beyond the cryptocurrency sector. A new investigation by SentinelLABS shows that two macOS backdoors FLATROOF and ROOFDECK that appeared in the LayerZero attack were discovered on the MacBook of a DevOps engineer at an IT service provider in India. The incident highlights the unique risks of programmer workstations: just one compromised device can lead to source code, cloud credentials, and the software supply chain.

Who is Jade Sleet?

Jade Sleet is described by Microsoft and cybersecurity firms as an operating group backed by the North Korean state, with a focus on financial goals. The group often approaches software engineers, blockchain personnel, and job seekers with fake resumes, programming tests, or seemingly legitimate GitHub projects. The goal is not just a cryptocurrency wallet; An engineer's access to code repositories, CI/CD pipelines, API keys, and cloud platforms can deliver much greater value.

In 2026, TraderTraitor was linked to the LayerZero Labs hack, which was later used to support a fake cryptocurrency minting transaction and caused approximately $292 million in losses to KelpDAO, as reported by SentinelOne. Analysis of the incident revealed FLATROOF and ROOFDECK, two backdoors written in Rust for Macs using ARM64 architecture.

Fake interview decoys and weaponized Terraform files

The attack chain begins with “Contagious Interview” style social engineering. The attacker pretends to be a recruiter, sending the candidate an infrastructure assignment in the form of a GitHub repository. Recorded warehouse names include: Northwind-IAC, novacart-interview and terraform-candidate-repo, designed to fit the victim's DevOps or FinTech job.

The danger point is in the dependency key file .terraform.lock.hcl. This file points Terraform to fake provider domains such as registry.hashicorp-aws[.]com instead of legitimate sources. When the candidate runs terraform init,Terraform trusts the source declared in the key file, loads the ,attacker controlled module and executes it on the development machine. An operation that is considered normal in a recruitment test thus becomes a step in installing malicious code.

Kho GitHub chứa bài kiểm tra Terraform bị Jade Sleet vũ khí hóa
The recruitment test on GitHub contained a Terraform file pointing to a fake vendor. Photo: SentinelLABS

DevOps engineer's Mac penetration timeline

SentinelLABS said the additional victim was a small-scale IT services company in India, with no direct ties to cryptocurrency. The affected device is an Apple Silicon MacBook belonging to a DevOps engineer who regularly uses Terraform and Ansible to administer AWS, OVH, and OpenStack. The machine also stores cloud credentials and source code repository access.

  • 18/3/2026: Surveillance data showed that FLATROOF and ROOFDECK existed on the machine, but there was insufficient evidence to determine how they were delivered.
  • 29/3/2026: seconds after workspace cloudshield Opened in Cursor, the two implants are activated, connected to the control infrastructure and removed from the macOS isolation properties.
  • March 30–April 19, 2026: The backdoor emits a regular signal when the Cursor is active and is silent when the application is closed, helping malicious traffic blend into the normal working rhythm.
  • 13/4/2026: warehouse copy engineer terraform-candidate-repo using GitHub Desktop.
  • 20/4/2026: ROOFDECK loads a third stage payload named loginwindow, then the new payload erases the two original implants to reduce the footprint.
  • 1/6/2026: SentinelLABS records the last control signal in the collected data set.

The above sequence does not prove that Cursor is the source of infection. This tool appears as a parent process when the workspace is open and the integrated terminal environment is activated; Malicious code may have been installed through a project or manipulated shell configuration. This is an important distinction to avoid misattributing legitimate software.

FLATROOF: collect data and pave the way

FLATROOF, also known as macOS.Gaslight, is installed under the name SystemUpdate in the user directory to create a sense of legitimacy. The backdoor can run commands, stop processes, upload or download files, and deploy the next payload. It also carries a Python module to collect Chrome, Brave, Firefox and Safari browser data, terminal command history, application list, running processes, hardware and software information, and database copy. login.keychain-db.

Data can be exported via Telegram using the embedded bot token. FLATROOF also removes the attribute com.apple.quarantine from ROOFDECK and grant execute permission, weakening an important layer of Gatekeeper protection without displaying the familiar warning to the user.

ROOFDECK: sustainable control and horizontal movement

ROOFDECK is a later stage tool, with a broader range of functions. It supports system reconnaissance, interactive shells, loading and unloading data, file manipulation, creating encrypted archives, updating itself, and maintaining presence using Launch Agent. The control command is signed with the operator's private key and checked with the public key embedded in the implant before execution.

Instead of depending on a fixed server, ROOFDECK can use the Nostr network as a “dead spot” mechanism to find the current C2 address. Implant queries the Nostr profile controlled by the attacker, reads the website field, and then uses that value as the control server. This design helps operators change infrastructure flexibly and makes it difficult to block by single domain name.

Why is DevOps machine a strategic target?

A DevOps workstation typically connects to multiple sensitive areas simultaneously: Git repositories, CI/CD pipelines, software registry, secrets management system, cloud accounts, and production environments. Therefore, the value of the target does not depend on the size of the company but on what the laptop can access. A small IT service provider can also become a springboard to attack many customers.

The incident also shows that the lines between recruitment fraud and supply chain attacks are blurring. Instead of exploiting a common software vulnerability, the attacker injects malicious code into the very workflow the engineer is asked to perform. Personalized projects for each victim make traditional detection signatures and generic training campaigns less effective.

Defense recommendations for individuals and organizations

  • Do not run recruitment tests or strange projects on company computers; Use isolated virtual machines, unprivileged accounts, and environments that do not contain physical keys.
  • Check .terraform.lock.hcl, required_providers, installation script and registry domain name before running terraform init; Be wary of domain names similar to HashiCorp.
  • Separation of credentials from workstations, prioritization of short-term tokens, anti-phishing MFA, and minimal access permissions for Git, CI/CD, and cloud platforms.
  • Monitor quarantine attribute changes, Launch Agents, system service impersonation processes, and unusual connections to Telegram, Nostr, or newly registered domains.
  • Rotate API keys and investigate cloud logs as soon as development machines show signs of compromise; processing is not limited to deleting malicious code on the endpoint.
  • Develop a process to verify employers and report suspicious tests to security before opening or executing code.

Lessons from Jade Sleet profile

Jade Sleet is exploiting an organizational weakness: the pressure to complete technical testing and the habit of trusting familiar development tools. The incident at the Indian IT services provider shows that even organizations that do not own crypto assets can still be targeted if their personnel have valuable access.

Effective defense requires combining technical controls with changes to recruitment and development processes. Any code of unknown origin should be considered untrusted, and engineer workstations should be protected to the same level as a privileged system. As endpoints grow to become the center of the attack chain, source code, cloud identity, and endpoint security cannot continue to be managed as three separate problems.

VNCyberS compiled from SentinelLABS and The Hacker News

Contact Us

Email: [email protected]
Phone: +84 903260277