AI Weekly Malaysia

Back to items Summaries

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

ID
26744
Status
summarized
Published
21 Sep 2026, 2:06 PM
Fetched
21 Sep 2026, 2:36 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
21 Sep 2026, 2:36 PM
Tags
Audience
developersai_agent_userssaas_founders

What happened

SentinelOne attributed a breach of an India-based IT services company to the North Korean threat actor Jade Sleet, who used fake job interview lures to get developers to clone weaponized GitHub repositories. Running `terraform init` on these repos triggered download of malicious modules via spoofed domains like registry.hashicorp-aws[.]com, ultimately deploying Rust-based macOS backdoors FLATROOF and ROOFDECK on ARM-based Macs.

Why it matters

If you or your team handles candidate coding assessments or Terraform repos from interviews, treat any `.terraform.lock.hcl` pointing at non-standard registries as suspicious—verify the domain before running `terraform init`. This is especially relevant for Malaysian dev shops that outsource hiring or accept repos from unfamiliar candidates, since the attack targets DevOps and fintech developers specifically.

Discussion angle

How should hiring teams vet take-home repos and Terraform projects from candidates without running untrusted infrastructure-as-code on company machines?

Top