North Korea-linked threat actors abuse VS Code auto-run to spread StoatWaffle malware
ID: 204e3f6e-9da5-53d9-96b5-3184f164eaa1
STIX ID: report--204e3f6e-9da5-53d9-96b5-3184f164eaa1
Feed Name: Security Affairs
North Korea-linked threat actor Team 8 (Contagious Interview) is spreading StoatWaffle by abusing Visual Studio Code's tasks.json auto-run capability: malicious VS Code projects execute on folder open to download a multi-stage Node.js-based loader from web hosts (e.g., Vercel), install Node.js if needed, and fetch additional modules. StoatWaffle includes a stealer that exfiltrates browser credentials, extension data, installed software details and macOS Keychain entries, plus a RAT for remote command execution, enabling broad data theft and remote control across operating systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
