Threats · 16h ago

Jade Sleet Used Terraform to Reach Developer Macs

SentinelOne tied North Korean actor Jade Sleet to a breach of an India-based IT services provider after finding FLATROOF and ROOFDECK on a DevOps engineer’s MacBook. The case adds another developer-focused intrusion to a group also known as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899.

The access path was Terraform, the infrastructure-as-code tool used to assemble cloud environments. SentinelOne says the attackers planted a fake dependency reference in the `.terraform.lock.hcl` file so that when the engineer ran `terraform init`, the machine reached out to attacker-controlled infrastructure and downloaded malicious modules, turning a normal build step into code execution on the developer endpoint.

The important boundary is the repo and its lockfile, not just the Mac itself. If Terraform runs from engineer laptops, a poisoned build input can become entry into shared infrastructure and a foothold that survives beyond a single compromised workstation.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-21

Editions

Related stories