logo

North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware

ID: 2c460ba6-d46c-54ea-91cb-acac03c841f8

STIX ID: report--2c460ba6-d46c-54ea-91cb-acac03c841f8

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-03-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

North Korean threat actors (WaterPlum / Contagious Interview) are distributing a Node.js modular malware called StoatWaffle through malicious VS Code projects, npm packages, and compromised GitHub repositories; the malware includes stealer and RAT modules, uses tasks.json auto-run and multi-stage downloaders, and targets developers and cryptocurrency professionals via sophisticated social-engineering and supply-chain techniques. Vendors have introduced mitigations and law enforcement has pursued related criminal activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.