logo

WaterPlum Unleashes “StoatWaffle” Malware in VSCode Supply Chain Attack

ID: 395667ad-960c-56db-a4b4-78510116141e

STIX ID: report--395667ad-960c-56db-a4b4-78510116141e

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

StoatWaffle — a newly reported modular malware attributed to the North Korea-linked WaterPlum (Team 8) — is distributed through malicious VSCode repositories that auto-execute a tasks.json task when a developer opens and trusts the project. The chain installs or uses Node.js, fetches loaders (env.npl, vscode-bootstrap.cmd) from Vercel-hosted endpoints, and deploys stealer and RAT modules that exfiltrate browser credentials, extension data, macOS Keychain secrets, and system profiles while maintaining persistent C2 communications; the campaign specifically targets blockchain developers and abuses trusted development tooling, including WSL-aware path handling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.