Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
North Korea-linked TraderTraitor uses weaponized Terraform lock files in fake job-interview GitHub repos to deploy FLATROOF and ROOFDECK macOS backdoors on DevOps engineers.
SentinelOne reports that TraderTraitor (UNC4899, Jade Sleet, PUKCHONG), a DPRK-aligned Lazarus subgroup, expanded its Contagious Interview-style developer targeting beyond cryptocurrency victims, weaponizing .terraform.lock.hcl files to redirect terraform init to typosquatted registries such as registry.hashicorp-aws[.]com and registry.hashicorp-terraform[.]io. An India-based IT services provider was infected with FLATROOF (macOS.Gaslight) and ROOFDECK implants observed on disk from March 18, 2026, on an Apple Silicon MacBook administered by a DevOps engineer managing AWS, OVH and OpenStack infrastructure. FLATROOF persists via a LaunchAgents plist, removes the quarantine attribute to bypass Gatekeeper, and collects keychain, browser, and command history data, exfiltrating via Telegram, while ROOFDECK resolves C2 through Nostr relays as a dead-drop mechanism. The same implants were tied to the April 2026 KelpDAO rsETH bridge attack via LayerZero, in which 116,500 rsETH (~$292 million) was stolen, with attribution by LayerZero, Mandiant, and CrowdStrike.