HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

TraderTraitor Backdoors Resurface in macOS Systems of an IT Services Firm via Malicious Terraform Providers

SentinelOne identified macOS backdoors in a small IT‑services company, delivered through attacker‑controlled Terraform provider registries after a social‑engineering job‑interview lure. The incident underscores the need for continuous third‑party risk monitoring and auditable supply‑chain controls.

Verisq™ Intelligence · 📅 September 18, 2026 · 📰 sentinelone.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
sentinelone.com

TraderTraitor Backdoors Resurface in macOS Systems of an IT Services Firm via Malicious Terraform Providers

What Happened – SentinelOne discovered macOS backdoors (FLATROOF / ROOFDECK) in a small IT‑services company that were previously seen in the high‑profile LayerZero breach. The implants were delivered through malicious Terraform provider registries that the attackers controlled, using social‑engineering job‑interview lures to trick developers into pulling the compromised code.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a lack of continuous third‑party risk monitoring can let supply‑chain code (Terraform providers) become a covert infection vector.
  • Highlights the need for auditable evidence that all external code dependencies are vetted, tracked, and regularly scanned for malicious behavior.
  • Aligns directly with the control objective of Supply‑chain and third‑party risk management, a single VCF control that satisfies many frameworks (e.g., NIST CSF 2.0).

Who Is Affected – IT services and DevOps teams that rely on open‑source infrastructure‑as‑code tools; broader enterprises using Terraform or similar IaC pipelines.

Recommended Actions

  • Map your IaC supply‑chain controls to the VCF “third‑party risk management” objective and collect continuous monitoring evidence.
  • Implement automated scanning of all Terraform provider registries and enforce signed‑package verification before integration.
  • Conduct a focused audit of recent code pulls to identify any lingering malicious artifacts.

Source: SentinelOne Labs – Don’t Call Us, We’ll Call Your APIs

Technical Notes – The attackers leveraged fake job‑interview outreach to deliver malicious GitHub repositories containing custom Terraform providers. These providers, once added to lock files, executed macOS backdoors (macOS.Gaslight). No direct cryptocurrency ties were present in this victim.

📰 Original Source
https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →