Executive Summary
In March 2026, North Korean threat actor Jade Sleet compromised an Indian IT services provider through a sophisticated supply chain attack targeting a DevOps engineer's Apple Silicon MacBook. The attack employed social engineering via fake job interviews and weaponized Terraform dependency files hosted on malicious infrastructure mimicking HashiCorp's registry. The compromise deployed two advanced Rust-based backdoors - FLATROOF and ROOFDECK - enabling extensive system reconnaissance, data theft, and persistent access. The same tactics and tools were used in the high-profile KelpDAO LayerZero bridge attack that occurred in April 2026, highlighting the interconnected nature of supply chain compromises.
This incident exemplifies the evolving threat landscape where nation-state actors increasingly target third-party vendors and developer environments to gain access to larger organizational networks. The attack demonstrates how modern threat actors exploit trusted development tools and processes, making detection significantly more challenging and expanding the potential impact across multiple downstream organizations.
Why This Matters Now
Supply chain attacks targeting developer environments have increased 300% in 2026, with nation-state actors like Jade Sleet weaponizing trusted development tools like Terraform to compromise multiple organizations through single vendor breaches, making third-party risk management critically urgent.
Attack Path Analysis
Jade Sleet compromised an Indian IT services provider through social engineering targeting a DevOps engineer with malicious Terraform dependencies, establishing persistence with FLATROOF and ROOFDECK backdoors for reconnaissance and data collection, maintaining command and control through Telegram and Nostr protocols, and exfiltrating browser data, system profiles, and credentials to support broader supply chain attacks against cryptocurrency targets.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Social engineering campaign targeting DevOps engineer with job interview lure containing weaponized Terraform dependency lock file that downloads malicious modules from attacker-controlled domains when terraform init is executed
MITRE ATT&CK® Techniques
Spearphishing Attachment
Compromise Software Supply Chain
Malicious File
Launch Agent
Keychain
Web Protocols
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Developer Environment Security
Control ID: DE.3.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
NIS2 Directive – Supply Chain Security
Control ID: Article 21
Digital Operational Resilience Act (DORA) – ICT Third-Party Risk Management
Control ID: Article 11
PCI DSS 4.0 – Software Development Security
Control ID: 6.2.4
ISO 27001:2022 – Information Security in Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Direct targeting of IT service providers through supply chain compromise enables lateral movement to client networks, exposing critical infrastructure and development environments.
Computer Software/Engineering
Developer-focused social engineering attacks compromise software supply chains through weaponized Terraform dependencies, threatening code integrity and deployment security across organizations.
Financial Services
North Korean threat actors historically target cryptocurrency and blockchain firms through compromised IT vendors, creating systemic risks for financial institutions and trading platforms.
Outsourcing/Offshoring
Third-party service providers face heightened risk as attack vectors for accessing client environments, particularly those offering DevOps and cloud infrastructure management services.
Sources
- Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoorshttps://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.htmlVerified
- Dont Call Us Well Call Your APIs TraderTraitor Backdoors Resurface on Victim with No Crypto Tieshttps://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/Verified
- KelpDAO Bridge Exploit Analysishttps://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/Verified
- KelpDAO Incident Reporthttps://layerzero.network/publications/kelpdao-incident-report.pdfVerified
- LayerZero KelpDAO Incident Statementhttps://layerzero.network/blog/kelpdao-incident-statementVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain Jade Sleet's supply chain attack by limiting lateral movement within the compromised IT provider's infrastructure and reducing the blast radius across cloud environments through segmented access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric may limit the blast radius of compromised Terraform infrastructure by constraining access to downstream cloud resources and reducing the scope of accessible deployment targets across multi-cloud environments.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain the backdoors' ability to access cloud resources by limiting privilege scope and reducing lateral access to sensitive development infrastructure even with compromised developer credentials.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely limit the backdoors' ability to move between cloud workloads and DevOps infrastructure, constraining access to pipeline resources and reducing reachability across development and production environments.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls may constrain C2 communications by limiting outbound connectivity from cloud workloads and reducing the attackers' ability to maintain persistent command channels across different cloud environments and services.
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely constrain data exfiltration by limiting outbound data transfers from cloud environments and reducing the attackers' ability to extract sensitive information through unauthorized external connections.
While initial compromise may still occur, segmented cloud infrastructure would likely reduce the overall impact by limiting the compromised provider's ability to access customer environments and constraining the scope of downstream supply chain attacks.
Impact at a Glance
Affected Business Functions
- DevOps and Infrastructure Management
- Software Development
- Cloud Services Management
- Client IT Support Services
Estimated downtime: 7 days
Estimated loss: N/A
DevOps engineer credentials, system configuration data, browser stored data including passwords and authentication tokens, macOS keychain data, terminal command histories, system hardware profiles, and potentially client infrastructure access credentials through the compromised IT services provider environment
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate developer workstations and limit access to critical infrastructure based on identity and device posture
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized outbound communications to suspicious domains and C2 channels
- • Enable East-West Traffic Security monitoring to detect lateral movement between developer environments and production cloud resources
- • Establish Multicloud Visibility & Control to monitor anomalous API calls and automation activities across development pipelines
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal developer behavior and alert on suspicious tool usage patterns



