TraderTraitor Backdoors Resurface in macOS Systems of an IT Services Firm via Malicious Terraform Providers
What Happened – SentinelOne discovered macOS backdoors (FLATROOF / ROOFDECK) in a small IT‑services company that were previously seen in the high‑profile LayerZero breach. The implants were delivered through malicious Terraform provider registries that the attackers controlled, using social‑engineering job‑interview lures to trick developers into pulling the compromised code.
Why It Matters for Trust & Control Assurance
- Demonstrates how a lack of continuous third‑party risk monitoring can let supply‑chain code (Terraform providers) become a covert infection vector.
- Highlights the need for auditable evidence that all external code dependencies are vetted, tracked, and regularly scanned for malicious behavior.
- Aligns directly with the control objective of Supply‑chain and third‑party risk management, a single VCF control that satisfies many frameworks (e.g., NIST CSF 2.0).
Who Is Affected – IT services and DevOps teams that rely on open‑source infrastructure‑as‑code tools; broader enterprises using Terraform or similar IaC pipelines.
Recommended Actions
- Map your IaC supply‑chain controls to the VCF “third‑party risk management” objective and collect continuous monitoring evidence.
- Implement automated scanning of all Terraform provider registries and enforce signed‑package verification before integration.
- Conduct a focused audit of recent code pulls to identify any lingering malicious artifacts.
Source: SentinelOne Labs – Don’t Call Us, We’ll Call Your APIs
Technical Notes – The attackers leveraged fake job‑interview outreach to deliver malicious GitHub repositories containing custom Terraform providers. These providers, once added to lock files, executed macOS backdoors (macOS.Gaslight). No direct cryptocurrency ties were present in this victim.