Threats · 16h ago
SentinelOne tied North Korean actor Jade Sleet to a breach of an India-based IT services provider after finding FLATROOF and ROOFDECK on a DevOps engineer’s MacBook. The case adds another developer-focused intrusion to a group also known as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899.
The access path was Terraform, the infrastructure-as-code tool used to assemble cloud environments. SentinelOne says the attackers planted a fake dependency reference in the `.terraform.lock.hcl` file so that when the engineer ran `terraform init`, the machine reached out to attacker-controlled infrastructure and downloaded malicious modules, turning a normal build step into code execution on the developer endpoint.
The important boundary is the repo and its lockfile, not just the Mac itself. If Terraform runs from engineer laptops, a poisoned build input can become entry into shared infrastructure and a foothold that survives beyond a single compromised workstation.
1 source covering this story
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Jade Sleet compromised an Indian IT services provider through a DevOps engineer’s MacBook, where FLATROOF and ROOFDECK were detected.
Part of the PlainSec briefing for 2026-09-21