Researchers have linked North Korean threat actor Jade Sleet to the compromise of an India-based IT services provider, where two macOS backdoors were found on a DevOps engineer’s Apple Silicon MacBook.
The case reinforces a recurring supply-chain strategy: compromise a developer or technology vendor whose workstation provides access to cloud infrastructure, source code and customer environments.
FLATROOF and ROOFDECK
SentinelOne found two Rust-based backdoors previously associated with an attack on KelpDAO’s LayerZero bridge.
- FLATROOF, also known as Gaslight, uses Telegram for command and control. It can execute commands, transfer files and collect browser data, terminal history, process information, application inventories and the macOS login keychain database.
- ROOFDECK uses the decentralized Nostr protocol for command and control. It supports reconnaissance, file operations, remote shell access, lateral movement and persistence through Launch Agents. Commands are cryptographically signed before the implant accepts them.
The backdoors were present on the developer’s machine by March 18 but remained dormant until March 29. Activity began seconds after the Cursor editor opened a workspace named cloudshield, suggesting that a weaponized development project may have triggered the implants. Researchers have not confirmed the initial delivery mechanism for this victim.
An updated ROOFDECK variant appeared on April 20. It removed earlier malware binaries and stripped symbols and debugging information, likely to make analysis more difficult.
Job lures and developer tooling
Jade Sleet has used fake coding interviews and repositories tailored to DevOps, cryptocurrency and financial-technology roles. Observed projects included malicious Terraform dependency lock files that pointed to attacker-controlled lookalike domains. Running terraform init could then retrieve a hostile module.
Defensive priorities
- Run interview exercises and unfamiliar repositories only in isolated, disposable environments.
- Restrict developer credentials to short-lived, hardware-backed sessions.
- Monitor dependency lock files and block lookalike package registries.
- Alert when IDEs spawn unexpected binaries, Launch Agents or network connections.
- Review outbound Telegram and Nostr traffic from developer endpoints.
- Segment developer workstations from production and customer environments.
Security teams should treat the developer endpoint as a privileged supply-chain asset rather than a conventional office workstation.
