logo

WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign

ID: 2ae75345-0d8d-5973-891d-a4610a577587

STIX ID: report--2ae75345-0d8d-5973-891d-a4610a577587

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-03-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

StoatWaffle is a new, modular Node.js malware deployed by North Korea-linked WaterPlum (Team 8) via fake VSCode blockchain project repositories that exploit VSCode workspace trust and runOn:folderOpen to silently execute a bootstrapper, install Node.js if necessary, and fetch staged loaders that deploy credential-stealing and RAT modules; NTT Security’s March 17, 2026 report includes C2 IPs and IOCs and recommends restricting runOn:folderOpen, monitoring unexpected Node.js installs, and blocking listed IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.