A North Korean cyber group, identified as Jade Sleet, recently infiltrated an Indian IT services company, marking another instance of their targeted attacks on developers. The breach, disclosed by cybersecurity firm SentinelOne, involved macOS backdoors known as FLATROOF and ROOFDECK. These backdoors were previously seen in attacks on the LayerZero bridge of KelpDAO earlier in 2026.
Background on Jade Sleet’s Activities
Jade Sleet, also referred to as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899, has a notorious history in the Web3 space, often targeting cryptocurrency assets. In 2025, the group was linked to a massive $1.5 billion heist from Bybit’s cold wallet infrastructure, accomplished through a supply chain attack on Safe{Wallet}’s developer setup.
According to Microsoft-owned GitHub, Jade Sleet’s primary targets include entities involved in cryptocurrency and blockchain, as well as vendors servicing these sectors. The group’s tactics often involve social engineering, specifically luring job seekers from compromised firms through fake job interviews.
Technical Details of the Attack
The attackers utilized GitHub repositories themed as infrastructure projects to deceive developers into executing malicious code. Some repositories involved include gtn-candidate-repo, Northwind-IAC, and novacart-interview, which contain a malicious Terraform dependency lock file. By manipulating these files, developers unknowingly download harmful modules during the ‘terraform init’ command execution.
Two distinct malware families, FLATROOF and ROOFDECK, were deployed, targeting ARM-based macOS systems. FLATROOF operates via Telegram for command-and-control, capable of executing commands and stealing data. Meanwhile, ROOFDECK uses the decentralized Nostr protocol for similar purposes, including system reconnaissance and file manipulation.
Implications and Future Outlook
The discovery of these backdoors on a DevOps engineer’s Apple Silicon MacBook in India underlines the persistent risk posed by such sophisticated cyber threats. The malware remained inactive until March 29, when suspicious activities were detected. An updated variant of ROOFDECK was later installed, further complicating detection efforts.
SentinelOne emphasizes the need for heightened vigilance, especially on developer endpoints, which are critical to accessing cloud services and source codes. The reliance on software supply chains for initial access poses a significant cybersecurity challenge, necessitating robust monitoring and defense strategies to protect sensitive development environments from targeted cyber attacks.
