WaterPlum, a North Korea-linked threat group, has introduced a new modular malware family called StoatWaffle in its Contagious Interview campaign, replacing the previously used OtterCookie for activity attributed to Team 8 (also tracked as Moralis or Modilus). The malware is being delivered through malicious blockchain-themed repositories that abuse VSCode workspace trust and .vscode/tasks.json with runOn: folderOpen, causing code to execute when a victim opens and trusts the project. The initial task downloads payloads from a Vercel-hosted web application, launches cmd.exe, retrieves vscode-bootstrap.cmd, checks for Node.js, installs it if absent, and then runs env.npl and package.json to begin the staged infection chain.
NTT Security’s analysis describes StoatWaffle as a Node.js-based, multi-stage framework composed of a loader, a stealer, and a RAT component. The first-stage loader polls the C2 endpoint /api/errorMessage every five seconds and executes returned Node.js code, while a second-stage downloader contacts /api/handleErrors to fetch additional code and deploy follow-on modules. The stealer targets browser-stored credentials and extension data from Chromium-based browsers and Firefox, and on macOS also targets Keychain data, staging stolen files in randomly named temporary directories before uploading them to /upload. Reference 0 is a secondary report summarizing NTT’s findings, while References 1 and 2 are the original Japanese and English NTT writeups describing the same malware, delivery chain, and victim data theft behavior.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft introduced protections in Visual Studio Code versions 1.109 and 1.110 to mitigate abuse of tasks.json auto-run behavior, disabling automatic tasks by default and warning users about auto-run tasks in newly opened workspaces. The changes were reported in connection with WaterPlum's use of malicious VS Code projects to deliver StoatWaffle.
NTT Security Japan published analysis of StoatWaffle, describing its multi-stage loader, stealer, and RAT modules, along with data theft targets including browser credentials, browser extension data, installed software information, macOS Keychain data, and Windows-side data accessible from WSL environments.
In the StoatWaffle attack chain, WaterPlum distributed blockchain-themed malicious Visual Studio Code repositories that abused .vscode/tasks.json with the runOn: folderOpen setting to execute code when victims opened and trusted the project. The chain then downloaded staged payloads from a Vercel-hosted application and contacted command-and-control infrastructure to fetch additional Node.js code.
Around December 2025, WaterPlum's Team 8 cluster in the Contagious Interview campaign began replacing its previously used OtterCookie malware with a newly identified modular Node.js malware family called StoatWaffle.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourceinfoworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcejp.security.ntt
Open sourcejp.security.ntt
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.