StoatWaffle is a modular Node.js-based malware family associated with the North Korea-linked WaterPlum threat actor, also tracked as Team 8, and the Contagious Interview campaign. Active since approximately December 2025, it targets software developers and cryptocurrency, blockchain, and Web3 professionals through fraudulent recruitment activity and blockchain-themed developer projects. The infection chain abuses automatic task execution in malicious Visual Studio Code workspaces and deploys staged downloader components that retrieve its primary modules.
StoatWaffle combines an information-stealing component with a remote-access trojan component. Its stealer collects credentials and extension data from Chromium-derived browsers and Firefox, and targets Keychain data on macOS. It can identify Windows Subsystem for Linux environments and access Windows user data from that context, then stages and uploads collected information to attacker-controlled infrastructure. Its RAT maintains command-and-control communications and supports directory and file enumeration, file uploads, arbitrary shell-command execution, and execution of Node.js code. These capabilities enable credential theft, data exfiltration, and post-compromise remote control of developer workstations, potentially providing access to source code, cloud resources, and cryptocurrency-related assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“NTT Security identified StoatWaffle as a newer WaterPlum malware family that emerged around December 2025. It combines stealing and remote-access capabilities and is implemented using Node.js.”
The malware, dubbed StoatWaffle, has been attributed to a group tracked as WaterPlum, also known as Team 8, Moralis, or the Modilus family. The malware is a modular implant written in Node.js and includes capabilities for stealing credentials and providing remote access to compromised systems.
The malware, dubbed StoatWaffle, has been attributed to a group tracked as WaterPlum, also known as Team 8, Moralis, or the Modilus family. The malware is a modular implant written in Node.js and includes capabilities for stealing credentials and providing remote access to compromised systems.
The malware, dubbed StoatWaffle, has been attributed to a group tracked as WaterPlum, also known as Team 8, Moralis, or the Modilus family. The malware is a modular implant written in Node.js and includes capabilities for stealing credentials and providing remote access to compromised systems.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
“Node.js spawning shell interpreters; Python spawning command shells; VS Code initiating unexpected network connections,” and malicious “.vscode/tasks.json” configurations capable of executing commands.
This task downloads and executes a batch file from a web application hosted on Vercel.
“BeaverTail is JavaScript-based malware hidden inside Node Package Manager (NPM) packages”; “OtterCookie is a JavaScript-based Remote Access Trojan.”
This file uses the runOn: folderOpen option, which instructs VS Code to execute a defined task as soon as the folder is opened and trusted by the user.
“Other sensitive data targeted for exfiltration includes: Clipboard information, key-logs (recorded keystrokes), screenshots.”
Stealer Module: This component is designed to exfiltrate credentials and data from Chromium-based browsers and Mozilla Firefox. It also targets browser extension data.
“Other sensitive data targeted for exfiltration includes: Cryptocurrency-wallet data (private key, seed phrase, etc.).”
One module acts as a stealer, collecting credentials from browsers, extension data, installed software details...
The RAT Module... include[s] the ability to list files, execute shell commands, upload files, and run arbitrary Node.js code.
The stealer can also detect if it is running in a Windows Subsystem for Linux (WSL) environment and access Windows user data from within the Linux instance.
Detection guidance calls for monitoring “Access to cryptocurrency-wallet directories,” “browser credential stores,” and reads of “SSH credentials.”
“Other sensitive data targeted for exfiltration includes: Clipboard information, key-logs (recorded keystrokes), screenshots.”
The RAT module maintains regular communication with an attacker-controlled C2 server, executing commands to terminate its own process, change the working directory, list files and directories, navigate to the application directory, retrieve directory details, upload a file, execute Node.js code, and run arbitrary shell commands, among others.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Node.js-based malware combining information-stealing and remote-access capabilities. It checks for WSL environments and converts Windows user-profile paths for access from Node.js.
A malware strain identified in WaterPlum operations targeting job applicants through fraudulent recruitment files to compromise devices and steal cryptocurrency-related credentials.
A modular Node.js malware family delivered via malicious VS Code projects abusing auto-run tasks.json. It uses a multi-stage infection chain with a loader/downloader, a credential and browser-extension data stealer, and a RAT module for remote command execution. It can steal macOS Keychain data and access Windows data through WSL environments.
StoatWaffle is a malware family with RAT and credential-stealing functionality. It communicates with a C2 server, executes commands, uploads files, runs Node.js and shell commands, steals stored browser credentials and browser extension data from Chromium and Firefox, and targets macOS Keychain databases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.