Cybersecurity & Privacy — 2026-03-23
North Korean WaterPlum Hackers Deploy StoatWaffle Malware via VS Code Auto-Run Tasks
North Korean threat group WaterPlum (aka Contagious Interview) is deploying the modular StoatWaffle malware through VS Code's tasks.json 'runOn: folderOpen' feature, triggering execution whenever any project file is opened. The Node.js malware steals credentials from Chromium/Firefox browsers and iCloud Keychain on macOS, plus provides remote access capabilities. Primary targets are cryptocurrency/Web3 founders, CTOs, and senior engineers compromised through fake job interviews via LinkedIn and GitHub. The malware downloads Node.js if absent, then periodically retrieves payloads from external servers.