Don’t just shout “it’s on-chain” and “it blew up again” at every security incident—this time, it really isn’t.
Wu Shuo reports that security firm SentinelOne released a report stating that researchers found macOS backdoors FLATROOF and ROOFDECK—similar to those used in the earlier LayerZero attack—on DevOps engineers’ devices at an Indian IT services company that is not related to the crypto industry. The activity was attributed to the North Korean Lazarus hacking group’s TraderTraitor/Jade Sleet unit, which previously took part in an attack that led to a $292 million loss for KelpDAO. According to the announcement/report, the attackers targeted developers via fake recruitment interviews and GitHub projects into which malicious code was implanted, tricking victims into running malware. The backdoor on the device was first observed as early as March 18, but the exact infection vector has not yet been confirmed. This is not a new on-chain smart contract vulnerability—indirect emotional pressure for $ZRO .
One observation is that attackers are expanding their targets from crypto projects to developers’ endpoints and supply-chain entry points—cloud credentials, code repositories, and CI/CD privileges could all become the next stepping stones. Another observation is that project teams, market makers, hosting providers, and cross-chain related groups really should re-check their macOS development environments, Terraform dependencies, and any abnormal IDE startup behavior. Do you think this kind of supply-chain risk is more likely to surface first in the hiring-phishing stage, or in the open-source dependency poisoning stage?
Figure 1: A LayerZero-related backdoor resurfacing at an Indian IT company · Source page partial screenshot
Image source: https://www.wublock123.com/news/security-firm-indian-it-firm-finds-macos-backdoor-like-layerzero-attack-68754
Wu Shuo reports that security firm SentinelOne released a report stating that researchers found macOS backdoors FLATROOF and ROOFDECK—similar to those used in the earlier LayerZero attack—on DevOps engineers’ devices at an Indian IT services company that is not related to the crypto industry. The activity was attributed to the North Korean Lazarus hacking group’s TraderTraitor/Jade Sleet unit, which previously took part in an attack that led to a $292 million loss for KelpDAO. According to the announcement/report, the attackers targeted developers via fake recruitment interviews and GitHub projects into which malicious code was implanted, tricking victims into running malware. The backdoor on the device was first observed as early as March 18, but the exact infection vector has not yet been confirmed. This is not a new on-chain smart contract vulnerability—indirect emotional pressure for $ZRO .
One observation is that attackers are expanding their targets from crypto projects to developers’ endpoints and supply-chain entry points—cloud credentials, code repositories, and CI/CD privileges could all become the next stepping stones. Another observation is that project teams, market makers, hosting providers, and cross-chain related groups really should re-check their macOS development environments, Terraform dependencies, and any abnormal IDE startup behavior. Do you think this kind of supply-chain risk is more likely to surface first in the hiring-phishing stage, or in the open-source dependency poisoning stage?
Figure 1: A LayerZero-related backdoor resurfacing at an Indian IT company · Source page partial screenshot
Image source: https://www.wublock123.com/news/security-firm-indian-it-firm-finds-macos-backdoor-like-layerzero-attack-68754
