WaterPlum Unleashes “StoatWaffle” Malware in VSCode Supply Chain Attack
ID: 395667ad-960c-56db-a4b4-78510116141e
STIX ID: report--395667ad-960c-56db-a4b4-78510116141e
Feed Name: GBHackers
StoatWaffle — a newly reported modular malware attributed to the North Korea-linked WaterPlum (Team 8) — is distributed through malicious VSCode repositories that auto-execute a tasks.json task when a developer opens and trusts the project. The chain installs or uses Node.js, fetches loaders (env.npl, vscode-bootstrap.cmd) from Vercel-hosted endpoints, and deploys stealer and RAT modules that exfiltrate browser credentials, extension data, macOS Keychain secrets, and system profiles while maintaining persistent C2 communications; the campaign specifically targets blockchain developers and abuses trusted development tooling, including WSL-aware path handling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
