logo

New “StoatWaffle” Malware Emerges in North Korean “Contagious Interview” Campaign

ID: 20899f75-f236-5d52-a4d4-bbf9726f13c8

STIX ID: report--20899f75-f236-5d52-a4d4-bbf9726f13c8

Feed Name: securityonline.info

Threat Score
82/100

Date Published: 2026-03-23

Date Updated: 2026-04-23

Author: Ddos

...
...

NTT Security Japan researchers discovered StoatWaffle, a Node.js-based modular malware used by North Korean-linked WaterPlum Team 8. The campaign uses malicious Git/VSCode repositories that auto-trigger a tasks.json task on folder open to download a bootstrap, install Node.js if needed, and deploy a downloader (env.npl) that launches modules for credential theft (browsers, extensions, macOS Keychain) and a RAT that persists and polls C2; the malware also converts Windows paths for access via WSL.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.