The Jade Sleet North Korean threat actor has once again targeted a smaller Indian IT service company, underscoring the persistent threat against developers This article explores terraform lock. . In early 2025, the hacking group was linked to the theft of approximately $1.5 billion from Bybit's cold wallet infrastructure following a supply chain compromise of Safe{Wallet}'s developer environment.

Security researchers Albert Priego, Alex Delamotte, and Matej Havranek noted that the GitHub repository themes for coding projects are designed to resemble infrastructure engineering projects related to the company the North Korean actors are impersonating. These repositories contain a weaponized Terraform dependency lock file (".terraform.lock.hcl") that points to malicious domains (e.g., "registry.hashicorp-aws[. ]com"), causing the platform to download attacker-controlled modules when the "terraform init" command is run by unsuspecting developers.

FLATROOF is a backdoor that uses Telegram for command-and-control (C2) and can execute commands, upload and download files, and steal data through a Python module that collects Chrome, Brave, Firefox, and Safari browser data, Terminal command histories, installed applications, system hardware and software profiles, running processes, and a login.keychain-db backup. An updated version of ROOFDECK, deployed on a DevOps engineer's system on April 20, 2026, a day after LayerZero acknowledged the KelpDAO hack, removes existing ROOFDECK and FLATROOF binaries and strips symbols and debug information to evade detection.