Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
- ID
- 26744
- Status
- summarized
- Published
- 21 Sep 2026, 2:06 PM
- Fetched
- 21 Sep 2026, 2:36 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 21 Sep 2026, 2:36 PM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
SentinelOne attributed a breach of an India-based IT services company to the North Korean threat actor Jade Sleet, who used fake job interview lures to get developers to clone weaponized GitHub repositories. Running `terraform init` on these repos triggered download of malicious modules via spoofed domains like registry.hashicorp-aws[.]com, ultimately deploying Rust-based macOS backdoors FLATROOF and ROOFDECK on ARM-based Macs.
Why it matters
If you or your team handles candidate coding assessments or Terraform repos from interviews, treat any `.terraform.lock.hcl` pointing at non-standard registries as suspicious—verify the domain before running `terraform init`. This is especially relevant for Malaysian dev shops that outsource hiring or accept repos from unfamiliar candidates, since the attack targets DevOps and fintech developers specifically.
Discussion angle
How should hiring teams vet take-home repos and Terraform projects from candidates without running untrusted infrastructure-as-code on company machines?