{"id":1872,"date":"2026-09-22T11:23:56","date_gmt":"2026-09-22T05:53:56","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1872"},"modified":"2026-09-24T09:49:04","modified_gmt":"2026-09-24T04:19:04","slug":"jade-sleet-flatroof-roofdeck-devops-macos","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/","title":{"rendered":"Jade Sleet FLATROOF and ROOFDECK: Securing DevOps Macs Against Backdoors"},"content":{"rendered":"<h2>Introduction<\/h2>\n<p>A coding assignment can look like routine work to an engineer who builds infrastructure every day.<\/p>\n<p>Research published on September 18, 2026, linked an Indian IT provider\u2019s compromised Mac to the Jade Sleet FLATROOF and ROOFDECK backdoors. Related activity used recruitment lures and weaponized development projects, but investigators could not confirm this device\u2019s original infection route.<\/p>\n<p>The case raises a practical question: what could someone reach after gaining control of a developer\u2019s laptop?<\/p>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Who is Jade Sleet?<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tJade Sleet is a North Korea-linked threat actor also known as TraderTraitor, PUKCHONG, and UNC4899. Its targeting includes cryptocurrency and blockchain organizations, along with vendors serving those businesses.<\/p>\n<p>The group impersonates recruiters or developers to build trust with technical employees. It then encourages targets to download repositories or run software containing malicious dependencies. These approaches turn familiar collaboration activities into opportunities for malware execution.<\/p>\n<p>FLATROOF (also known as Gaslight) and ROOFDECK previously featured in the KelpDAO bridge attack involving compromised LayerZero Labs infrastructure. Attackers deployed both macOS backdoors on a LayerZero developer\u2019s device during the intrusion.<\/p>\n<p>Its activity matters beyond cryptocurrency because technology vendors can hold valuable access to other organizations. For security teams, the relevant warning signs include unsolicited development invitations, unfamiliar dependencies, and requests to execute code during recruitment. Assess those requests independently of how convincing the sender\u2019s profile appears.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What happened?<\/h2>\n<p>The incident involved an Apple Silicon MacBook belonging to a DevOps engineer at an India-based IT services provider without cryptocurrency ties.<\/p>\n<table>\n<thead>\n<tr>\n<th>Area<\/th>\n<th>Verified details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Timeline<\/td>\n<td>Both backdoors were present by March 18, 2026. Observed execution began March 29; command-and-control activity continued into June.<\/td>\n<\/tr>\n<tr>\n<td>Execution<\/td>\n<td>Cursor launched the implants within seconds of opening the <code>~\/DevOps-Automation\/cloudshield<\/code> workspace. This does not establish a vulnerability in Cursor.<\/td>\n<\/tr>\n<tr>\n<td>Campaign lure<\/td>\n<td>Related GitHub projects posed as infrastructure engineering assessments and contained weaponized <code>.terraform.lock.hcl<\/code> files referencing attacker-controlled provider registries.<\/td>\n<\/tr>\n<tr>\n<td>FLATROOF<\/td>\n<td>Also called Gaslight, it supports command execution and collection of browser data, terminal history, system details, and a copy of <code>login.keychain-db<\/code>.<\/td>\n<\/tr>\n<tr>\n<td>ROOFDECK backdoor<\/td>\n<td>Supports remote shells, file operations, reconnaissance, and Launch Agent persistence. It uses the Nostr protocol for decentralized command-and-control address discovery. Before executing commands, it verifies the operator\u2019s cryptographic signatures using an embedded public key.<\/td>\n<\/tr>\n<tr>\n<td>Evidence limits<\/td>\n<td>Initial delivery remains unconfirmed. The report does not establish MFA bypass or downstream customer compromise.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>These findings distinguish observed endpoint activity from the wider campaign\u2019s delivery methods.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Zero-Touch-Enrollment-for-DaaS_-Why-It-Matters.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Why Zero-Touch Enrollment Matters for Device as a Service Deployments<\/h4><p>Zero-touch enrollment streamlines DaaS deployments, reduces IT workload and standardizes device setup.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/zero-touch-enrollment-for-daas\/\" aria-label=\"Why Zero-Touch Enrollment Matters for Device as a Service Deployments\"><\/a><\/div><\/div><\/div><\/p>\n<h3>Why the Terraform dependency matters<\/h3>\n<p>Terraform providers are executable plugins; modules are reusable infrastructure configurations. Calling both \u201cprovider modules\u201d obscures that distinction.<\/p>\n<p>During <code>terraform init<\/code>, Terraform installs required providers using configuration requirements and recorded lock-file selections. Checksums help verify package consistency, but an unfamiliar lock file does not establish that its selected dependencies are trustworthy. Before executing <code>terraform init<\/code>, inspect <code>.terraform.lock.hcl<\/code> for unofficial provider registry hostnames and verify their legitimacy.<\/p>\n<p>Review provider addresses, publishers, configuration files, and lock-file changes before initializing an external project. Treat a dependency review as a security decision, even when the project arrives through a plausible interview process.<\/p>\n<h2>Why this matters<\/h2>\n<p>Developer endpoints deserve protection based on the access they hold. A laptop used for infrastructure administration may provide routes into source repositories, deployment systems, or cloud resources.<\/p>\n<p>Consequently, a DevOps compromise can create exposure beyond local files. The actual impact depends on credential permissions, session validity, network access, and controls around connected services. Treat downstream access as something to investigate, rather than assume.<\/p>\n<p>Patching remains necessary, but teams must also address users executing untrusted code through legitimate tools. Similarly, successful authentication does not establish that every process running afterward is safe.<\/p>\n<p>Effective macOS developer endpoint security therefore needs several layers: controlled software use, limited privileges, dependency review, endpoint monitoring, and access policies. Each layer addresses a different part of the workflow.<\/p>\n<h2>How Hexnode can help<\/h2>\n<p>Hexnode can support the device-management and endpoint-response parts of this approach. Dependency validation and cloud permission reviews remain separate responsibilities.<\/p>\n<h4>Hexnode UEM: Control application access on developer Macs<\/h4>\n<p><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> supports application allowlisting and blocklisting on managed macOS devices. Administrators can define permitted applications or restrict access to selected apps, subject to agent and policy requirements.<\/p>\n<p>For development teams, use these controls to establish an approved toolset and restrict unnecessary applications. Test policies against real engineering workflows before broad deployment.<\/p>\n<p>Application controls should not be presented as a universal script or dependency filter. Allowlisting an IDE permits its normal code-execution workflows; it does not validate code or dependencies executed within that context. Dependency security requires isolation alongside application allowlisting. Run untrusted assessments in disposable, isolated environments without corporate credentials, mounted work directories, or access to production infrastructure. Teams still need procedures for reviewing external repositories and separating untrusted assessments from corporate access.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/macOS_thumbnail.webp?format=webp\" class=\"resource-box__image\" alt=\"macOS_thumbnail\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/macOS_thumbnail.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/macOS_thumbnail-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/macOS_thumbnail-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/macOS_thumbnail-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"macOS_thumbnail\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource \n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            macOS Platform Capability Statement\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download the infographic to explore how Hexnode simplifies macOS device management across every stage of the endpoint lifecycle.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/infographics\/macos-device-management\/'>\n                            Get the infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section> <\/p>\n<h4>Hexnode UEM: Bring device compliance into access decisions<\/h4>\n<p>Hexnode UEM can evaluate configured device requirements, including supported operating systems, encryption, and application checks. Through its supported integration with Microsoft Entra ID, Hexnode can supply device compliance information for Conditional Access decisions. Microsoft Entra ID enforces the configured access policy.<\/p>\n<p>Apply this approach to sensitive applications where the platform and integration support it. Validate coverage for each repository service and cloud console.<\/p>\n<p>Compliance helps establish a device baseline. It does not certify that a workstation is malware-free or automatically revoke every credential exposed through it.<\/p>\n<h4>Hexnode XDR: Investigate suspicious development activity<\/h4>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> supports endpoint investigation and response across Windows and macOS. Its documented response capabilities include device isolation, process termination, and file quarantine.<\/p>\n<p>For this threat pattern, prioritize monitoring parent-child process relationships where development IDEs spawn unrecognized command-line utilities or Rust binaries. Confirm that the available endpoint telemetry exposes the required process relationships before configuring these hunts. Investigate unexpected executable paths, command arguments, persistence changes, and outbound connections alongside the process activity.<\/p>\n<p>Treat these patterns as investigation leads: legitimate engineering workflows also launch command-line tools and compiled binaries. Evaluate them against approved development activity before taking containment action.<\/p>\n<h2>Strengthen developer workflows before the next assignment<\/h2>\n<p>Start by identifying developer devices with production access. Record which repositories, cloud roles, deployment systems, and secrets each device can reach. Reduce unnecessary permissions and avoid keeping production credentials in environments used for external coding assessments.<\/p>\n<p>Next, require review of unfamiliar repositories, provider sources, and lock files before execution. Run approved external assessments in isolated environments without corporate credentials, shared sensitive folders, or production connectivity. Give employees a clear way to report suspicious recruitment requests.<\/p>\n<p>If compromise is suspected, isolate the endpoint and preserve evidence. Review connected accounts, revoke affected sessions and tokens, and rotate exposed credentials from a trusted device. Investigate repository and deployment changes before restoring access.<\/p>\n<p>Hexnode UEM and Hexnode XDR can support this work through application controls, device compliance, investigation, and containment. Begin with the developer Macs that hold the broadest access, then verify that their permissions match current responsibilities.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f<\/h5><p>Sign up for Hexnode to strengthen developer device security and reduce risks across your macOS fleet.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today\u202f\u202f<\/a><\/div><\/div> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction A coding assignment can look like routine work to an engineer who builds infrastructure&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1896,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,14,15,17],"class_list":["post-1872","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-phishing","category-supply-chain-attack","category-malware","category-macos","product_category-unified-endpoint-management","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Jade Sleet FLATROOF and ROOFDECK: DevOps Mac Risks<\/title>\n<meta name=\"description\" content=\"Jade Sleet FLATROOF and ROOFDECK expose DevOps Mac risks. Learn how to strengthen device security, dependency checks, and access controls.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Jade Sleet FLATROOF and ROOFDECK: DevOps Mac Risks\" \/>\n<meta property=\"og:description\" content=\"Jade Sleet FLATROOF and ROOFDECK expose DevOps Mac risks. Learn how to strengthen device security, dependency checks, and access controls.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-22T05:53:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-24T04:19:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Jade-Sleet-FLATROOF-1.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"Jade Sleet FLATROOF and ROOFDECK: Securing DevOps Macs Against Backdoors\",\"datePublished\":\"2026-09-22T05:53:56+00:00\",\"dateModified\":\"2026-09-24T04:19:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/\"},\"wordCount\":1143,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Jade-Sleet-FLATROOF-1.png?format=webp\",\"articleSection\":[\"Phishing\",\"Supply Chain Attack\",\"Malware\",\"macOS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/\",\"name\":\"Jade Sleet FLATROOF and ROOFDECK: DevOps Mac Risks\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Jade-Sleet-FLATROOF-1.png?format=webp\",\"datePublished\":\"2026-09-22T05:53:56+00:00\",\"dateModified\":\"2026-09-24T04:19:04+00:00\",\"description\":\"Jade Sleet FLATROOF and ROOFDECK expose DevOps Mac risks. Learn how to strengthen device security, dependency checks, and access controls.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Jade-Sleet-FLATROOF-1.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Jade-Sleet-FLATROOF-1.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Jade Sleet FLATROOF\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/jade-sleet-flatroof-roofdeck-devops-macos\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Jade Sleet FLATROOF and ROOFDECK: Securing DevOps Macs Against Backdoors\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"description\":\"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Jade Sleet FLATROOF and ROOFDECK: DevOps Mac Risks","description":"Jade Sleet FLATROOF and ROOFDECK expose DevOps Mac risks. Learn how to strengthen device security, dependency checks, and access controls.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/","og_locale":"en_US","og_type":"article","og_title":"Jade Sleet FLATROOF and ROOFDECK: DevOps Mac Risks","og_description":"Jade Sleet FLATROOF and ROOFDECK expose DevOps Mac risks. Learn how to strengthen device security, dependency checks, and access controls.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-22T05:53:56+00:00","article_modified_time":"2026-09-24T04:19:04+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Jade-Sleet-FLATROOF-1.png?format=webp","type":"image\/png"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"Jade Sleet FLATROOF and ROOFDECK: Securing DevOps Macs Against Backdoors","datePublished":"2026-09-22T05:53:56+00:00","dateModified":"2026-09-24T04:19:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/"},"wordCount":1143,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Jade-Sleet-FLATROOF-1.png?format=webp","articleSection":["Phishing","Supply Chain Attack","Malware","macOS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/","url":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/","name":"Jade Sleet FLATROOF and ROOFDECK: DevOps Mac Risks","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Jade-Sleet-FLATROOF-1.png?format=webp","datePublished":"2026-09-22T05:53:56+00:00","dateModified":"2026-09-24T04:19:04+00:00","description":"Jade Sleet FLATROOF and ROOFDECK expose DevOps Mac risks. Learn how to strengthen device security, dependency checks, and access controls.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Jade-Sleet-FLATROOF-1.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Jade-Sleet-FLATROOF-1.png?format=webp","width":1340,"height":700,"caption":"Jade Sleet FLATROOF"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/jade-sleet-flatroof-roofdeck-devops-macos\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Jade Sleet FLATROOF and ROOFDECK: Securing DevOps Macs Against Backdoors"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"description":"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1872","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1872"}],"version-history":[{"count":7,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1872\/revisions"}],"predecessor-version":[{"id":1895,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1872\/revisions\/1895"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1896"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}