Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

TraderTraitor Backdoors Resurface in macOS Systems of an IT Services Firm via Malicious Terraform Providers

SentinelOne identified macOS backdoors in a small IT‑services company, delivered through attacker‑controlled Terraform provider registries after a social‑engineering job‑interview lure. The incident underscores the need for continuous third‑party risk monitoring and auditable supply‑chain controls.

LiveThreat™ Intelligence · 📅 September 18, 2026· 📰 sentinelone.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
sentinelone.com

TraderTraitor Backdoors Resurface in macOS Systems of an IT Services Firm via Malicious Terraform Providers

What Happened – SentinelOne discovered macOS backdoors (FLATROOF / ROOFDECK) in a small IT‑services company that were previously seen in the high‑profile LayerZero breach. The implants were delivered through malicious Terraform provider registries that the attackers controlled, using social‑engineering job‑interview lures to trick developers into pulling the compromised code.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a lack of continuous third‑party risk monitoring can let supply‑chain code (Terraform providers) become a covert infection vector.
  • Highlights the need for auditable evidence that all external code dependencies are vetted, tracked, and regularly scanned for malicious behavior.
  • Aligns directly with the control objective of Supply‑chain and third‑party risk management, a single VCF control that satisfies many frameworks (e.g., NIST CSF 2.0).

Who Is Affected – IT services and DevOps teams that rely on open‑source infrastructure‑as‑code tools; broader enterprises using Terraform or similar IaC pipelines.

Recommended Actions

  • Map your IaC supply‑chain controls to the VCF “third‑party risk management” objective and collect continuous monitoring evidence.
  • Implement automated scanning of all Terraform provider registries and enforce signed‑package verification before integration.
  • Conduct a focused audit of recent code pulls to identify any lingering malicious artifacts.

Source: SentinelOne Labs – Don’t Call Us, We’ll Call Your APIs

Technical Notes – The attackers leveraged fake job‑interview outreach to deliver malicious GitHub repositories containing custom Terraform providers. These providers, once added to lock files, executed macOS backdoors (macOS.Gaslight). No direct cryptocurrency ties were present in this victim.

📰 Original Source
https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →