North Korean Hackers Exploit Open Source Projects in Malware Attacks

www.news4hackers.com-north-korean-hackers-exploit-open-source-projects-in-malware-attacks-north-korean-hackers-exploit-open-source-projects-in-malware-attacks

North Korean Hackers Exploit Developer Projects to Deploy Malware – Cybersecurity Analysis

Threat Actor and Attack Overview

A North Korean threat actor known as Jade Sleet has been linked to the compromise of an India-based IT services provider, with attackers utilizing two previously documented macOS backdoors, FLATROOF and ROOFDECK. The incident highlights the growing risk of supply-chain attacks targeting developers and their infrastructure. The threat group, also tracked as UNC4899, has a history of focusing on the Web3 sector to steal cryptocurrency.

Previous Attacks and Targets

In early 2025, it was associated with the theft of approximately $1.5 billion from Bybit’s cold wallet infrastructure following a supply-chain breach of Safe{Wallet}’s developer environment. The group primarily targets individuals and organizations involved in cryptocurrency and blockchain technologies, as well as vendors supplying services to these entities.

Suspicious Activity on GitHub

Microsoft-owned GitHub reported suspicious activity tied to the group in July 2023. Attackers employ social engineering tactics, particularly job interview lures, to target developers. This method has been used by multiple North Korean threat groups to infiltrate companies that are later breached. Victims often hold roles in DevOps, cryptocurrency, or financial technology sectors.

Malicious GitHub Repositories

Malicious GitHub repositories mimic legitimate infrastructure projects for the organizations attackers impersonate. Examples include gtn-candidate-repo, Northwind-IAC, novacart-interview, and terraform-candidate-repo. The malicious code reaches victims through weaponized Terraform dependency lock files, specifically “.terraform.lock.hcl,” which direct the platform to malicious domains.

Malware Families: FLATROOF and ROOFDECK

This creates a pathway for deploying two Rust-based malware families designed for ARM-based macOS systems: FLATROOF and ROOFDECK. FLATROOF functions as a backdoor that communicates via Telegram for command-and-control operations. It can execute arbitrary commands, upload data, and download files. ROOFDECK, on the other hand, uses the Nostr protocol for decentralized command-and-control.

ROOFDECK Capabilities

ROOFDECK enables system reconnaissance, file manipulation, remote shell access, and persistence through macOS Launch Agents. ROOFDECK’s commands are signed with the operator’s private key and verified using an embedded public key. Its code is structured into separate handlers, and it can replicate common shell commands for directory and file operations, a technique seen in advanced North Korean toolsets.

Indian IT Provider Breach Details

The Indian IT provider’s breach occurred through an Apple Silicon MacBook used by a DevOps engineer. Backdoors were detected on the device as early as March 18, 2026, though the exact delivery method remains unclear. The implants remained inactive until March 29, when they began communicating with external servers.

Attack Timeline and Updates

Activity was triggered when the Cursor code editor was launched after opening the cloudshield workspace at ~/DevOps-Automation/cloudshield. Post-compromise, ROOFDECK was deployed as a follow-up tool after initial access was established. An updated version of ROOFDECK was reportedly installed on April 20, 2026, one day after LayerZero disclosed the KelpDAO hack.

Evading Detection

The newer variant removed existing FLATROOF and ROOFDECK binaries and stripped symbols and debug information to evade detection.

Implications and Risks

The attack underscores the vulnerability of developer systems, which serve as gateways to cloud environments, software pipelines, and source code. Attackers exploit third-party supply chains and development endpoints to gain access, bypassing direct organizational defenses. Developer systems pose a critical risk due to their access to sensitive infrastructure.

Security Recommendations

Attackers focus on individual engineers rather than targeting organizations directly, leveraging purpose-built development environments, malicious repositories, and backdoored Terraform builds. Legitimate-looking job interviews and coding projects can act as entry points for malware, particularly for developers in cryptocurrency, fintech, and DevOps roles.

The incident emphasizes the importance of securing developer endpoints, as they can provide access to broader corporate networks, cloud systems, and source code. It also highlights the need for caution with job-interview repositories and unfamiliar development projects, even if they appear technically legitimate. The use of weaponized Terraform files demonstrates how routine developer workflows can be exploited as part of an attack chain.



About Author

en_USEnglish