Jade Sleet Linked to Indian IT Provider Breach — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Jade Sleet, also tracked as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899, was attributed by SentinelOne to compromising a small India-based IT services organization through a DevOps engineer's Apple Silicon MacBook.
- SentinelOne researchers Albert Priego, Alex Delamotte, and Matej Havranek said the macOS backdoors FLATROOF (aka Gaslight) and ROOFDECK were previously observed in the March-April 2026 attack on KelpDAO's LayerZero bridge, and ROOFDECK re-implements shell functionality similar to Lazarus' LightlessCan.
- The campaign uses job interview lures and weaponized Terraform dependency lock files (.terraform.lock.hcl) pointing to malicious domains like registry.hashicorp-aws[.]com, which causes victim systems to download attacker-controlled modules when running "terraform init".
Why it matters: The implant sat dormant on the engineer's MacBook from March 18 to March 29 before activation via the Cursor workspace ~/DevOps-Automation/cloudshield, then a new ROOFDECK variant was deployed April 20 — one day after LayerZero publicly confirmed the KelpDAO hack — showing the actor adapts tooling in near-real-time after exposure. The pattern targets third-party IT vendors rather than crypto firms directly, meaning any organization relying on outsourced development pipelines is now part of the same blast radius.
Ask SkimNews




