logo

North Korea-linked threat actors abuse VS Code auto-run to spread StoatWaffle malware

ID: 204e3f6e-9da5-53d9-96b5-3184f164eaa1

STIX ID: report--204e3f6e-9da5-53d9-96b5-3184f164eaa1

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-03-24

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

North Korea-linked threat actor Team 8 (Contagious Interview) is spreading StoatWaffle by abusing Visual Studio Code's tasks.json auto-run capability: malicious VS Code projects execute on folder open to download a multi-stage Node.js-based loader from web hosts (e.g., Vercel), install Node.js if needed, and fetch additional modules. StoatWaffle includes a stealer that exfiltrates browser credentials, extension data, installed software details and macOS Keychain entries, plus a RAT for remote command execution, enabling broad data theft and remote control across operating systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.