Jade Sleet Hack of Indian DevOps MacBook Shows How One Laptop Can Expose Global IT Clients
Security researchers link North Korea‑associated group Jade Sleet to a breach of an Indian IT provider through a DevOps engineer’s Apple Silicon MacBook. The compromise, using custom tools called FLATROOF and ROOFDECK for remote access and data theft, highlights how a single development machine can become a pivot point into wider customer networks.
A single developer’s MacBook at an Indian IT provider has become the center of a new case study in software supply‑chain risk. According to a technical report, a DevOps engineer’s Apple Silicon‑based MacBook was compromised in an intrusion attributed to North Korean group Jade Sleet.
Investigators examining the breached system identified two pieces of custom malware, named FLATROOF and ROOFDECK. The tools were built to give attackers broad control: they enabled remote command execution, provided an interactive shell on the machine, maintained persistence across reboots, and supported theft of data from the compromised laptop.
For an attacker like Jade Sleet, a DevOps engineer is a valuable target. Staff in these roles often have access to source‑code repositories, continuous‑integration pipelines, and cloud infrastructure. If a threat actor controls that person’s laptop, it can potentially tamper with code before it’s built, intercept credentials, or move laterally into other parts of the IT provider’s environment.
Because the victim company is an IT services firm, the blast radius isn’t limited to one network. Such providers frequently work for multiple overseas clients, handling development, maintenance, or operations on their behalf. A compromise at the service provider level can, in some cases, open a path toward those downstream customer environments, even if those customers have invested heavily in their own internal defenses.
The tools found on the MacBook show that Apple Silicon hardware is now firmly in scope for state‑linked operators. While Apple’s platform brings its own security architecture, FLATROOF and ROOFDECK were evidently engineered to run on that hardware and stay resident, which points to sustained development effort.
Jade Sleet has been linked by previous research to North Korean state interests, including operations aimed at revenue generation and intelligence collection. Targeting a MacBook used in DevOps work at an Indian IT provider fits that pattern of going after nodes that sit close to valuable data and code, including in countries that serve as global outsourcing hubs.
For organizations that rely on third‑party development and operations teams, this case underlines a recurring problem: security gaps on a contractor’s laptop or build machine can undermine safeguards elsewhere in the chain. Controls that stop at a company’s own network perimeter don’t account for threat actors who choose to compromise the people and firms building or running its software.
What will matter now is whether any follow‑on compromises tied to this breach are identified among the provider’s clients, how quickly security vendors and defenders roll out detections for FLATROOF and ROOFDECK, and whether more Apple Silicon‑focused Jade Sleet activity surfaces in future incident reports.
Sources
- OSINT