North Korea-Linked Hackers Deploy StoatWaffle Malware via Visual Studio Code Projects

Listen to this Post

Featured Image

Introduction: A Silent Threat Hidden in Developer Tools

Cybersecurity threats are no longer confined to suspicious email attachments or obvious malicious downloads. Increasingly, attackers are embedding their operations into everyday tools used by developers worldwide. A recent campaign linked to the North Korean threat group Team 8 demonstrates just how dangerous this shift has become. By exploiting trusted development environments like Microsoft Visual Studio Code, attackers have found a way to execute malicious code the moment a project is opened, turning routine workflows into potential entry points for advanced cyberattacks.

Summary: How the Contagious Interview Campaign Delivers StoatWaffle

The threat actor known as Team 8, widely believed to be associated with North Korea, has expanded its cyber-espionage campaign, known as “Contagious Interview,” by introducing a new malware strain called StoatWaffle. Previously relying on malware like OtterCookie, the group shifted strategies in late 2025, deploying more advanced and modular tools to improve stealth and effectiveness.

At the center of this campaign is the abuse of a legitimate feature within Microsoft Visual Studio Code called “tasks.json.” This configuration file is designed to automate tasks within a project, but attackers have weaponized it to execute malicious scripts automatically when a user opens a compromised project folder. The attack begins when a victim downloads what appears to be a legitimate repository, often disguised as a blockchain-related project to attract developers. Once opened and trusted in the editor, the embedded tasks.json file triggers hidden commands.

These commands initiate a download sequence from external hosting services like Vercel, launching payloads through command-line execution. The malware first ensures that Node.js is installed on the victim’s system. If it is not present, the script installs it automatically, allowing the attack to proceed seamlessly across different operating systems including Windows, macOS, and Linux.

StoatWaffle operates through a multi-stage infection chain. The initial stage uses a Node.js-based loader that connects repeatedly to a command-and-control server, waiting for instructions. Once communication is established, a secondary downloader is deployed, enabling rapid delivery of additional malicious components.

One of these components functions as a data stealer. It targets sensitive information stored in web browsers, including login credentials, cookies, and extension data. The malware is particularly effective against Chromium-based browsers and Firefox, extracting extension configurations and identifying valuable targets through keyword matching. On macOS systems, it goes even further by accessing the Keychain database, which stores highly sensitive credentials.

Another module embedded within StoatWaffle acts as a remote access trojan, granting attackers full control over infected systems. This allows them to execute commands remotely, monitor activity, and extract additional data in real time. Notably, the malware can also access Windows data through Windows Subsystem for Linux environments, broadening its reach across hybrid system setups.

Security researchers from NTT Security emphasize that StoatWaffle is highly modular and continuously evolving. The group behind it, sometimes referred to as WaterPlum, is actively updating its malware toolkit, making detection and prevention increasingly difficult. The combination of automation, cross-platform compatibility, and stealth execution makes this campaign particularly dangerous for developers and organizations alike.

Technical Breakdown: The Strategic Evolution of Developer-Targeted Attacks

The shift toward exploiting development environments signals a calculated evolution in cyberattack strategies. Instead of relying on traditional phishing or exploit kits, attackers are embedding themselves into trusted workflows. By targeting developers directly, they gain access not only to individual machines but potentially to entire software supply chains.

The use of tasks.json is especially concerning because it leverages built-in functionality rather than exploiting a vulnerability. This means the attack does not rely on outdated software or unpatched systems. Instead, it exploits user trust. Once a developer opens a project and grants it permission, the malicious code executes without raising immediate suspicion.

The reliance on Node.js further enhances the attack’s flexibility. Node.js allows the malware to run consistently across different platforms, reducing the need for separate payloads. This cross-platform capability significantly increases the attack surface and simplifies deployment for the attackers.

Additionally, the modular design of StoatWaffle reflects a broader trend in modern malware development. Rather than delivering a single monolithic payload, attackers deploy lightweight components that can be updated or replaced dynamically. This makes detection harder and allows attackers to adapt quickly to security defenses.

What Undercode Say: Strategic Implications and Deeper Analysis

Developer Environments as the New Frontline

The targeting of development tools marks a critical turning point in cybersecurity. Developers operate in environments that inherently require high levels of trust, executing code from multiple sources daily. This makes them ideal targets for attackers seeking long-term access.

Trust Exploitation Over Vulnerability Exploitation

What stands out in this campaign is the absence of a traditional exploit. There is no zero-day vulnerability being abused. Instead, attackers are manipulating legitimate features. This indicates a shift from technical exploitation to psychological and workflow-based exploitation.

Supply Chain Risks Amplified

By compromising a developer’s environment, attackers can potentially inject malicious code into software projects. This creates downstream risks affecting users who may never interact with the original malicious repository.

Modular Malware as a Long-Term Threat

StoatWaffle’s modular architecture allows it to evolve continuously. Attackers can introduce new capabilities without redeploying the entire malware. This adaptability ensures longevity and resilience against traditional detection methods.

Cross-Platform Execution as a Force Multiplier

The use of Node.js eliminates many barriers typically faced in malware deployment. A single codebase can target multiple operating systems, making campaigns more efficient and scalable.

Stealth Through Legitimate Services

Hosting payloads on platforms like Vercel adds another layer of stealth. These services are widely trusted, making it less likely that network defenses will flag malicious traffic.

The Rise of Automated Execution Vectors

The abuse of auto-run configurations such as tasks.json highlights a growing trend. Automation features, designed to improve productivity, are increasingly being weaponized.

Defensive Challenges for Organizations

Traditional security measures may not detect such attacks because they do not involve suspicious binaries or known exploit signatures. Behavioral analysis and stricter project trust policies are becoming essential.

Human Factor Remains the Weakest Link

Despite all technical sophistication, the attack still relies on a user opening and trusting a malicious project. Awareness and training remain critical components of cybersecurity defense.

Continuous Evolution of Threat Actors

The involvement of a state-linked group suggests long-term strategic intent. These are not opportunistic attacks but carefully planned operations aimed at intelligence gathering and infrastructure compromise.

Fact Checker Results

✅ StoatWaffle uses tasks.json in Visual Studio Code to execute malicious code automatically.
✅ The malware includes both data-stealing and remote access trojan capabilities.
❌ There is no evidence that this attack exploits a software vulnerability; it relies on user trust.

Prediction

📊 The use of development tools as attack vectors will increase significantly, especially targeting open-source ecosystems.
📊 Modular malware like StoatWaffle will evolve faster, integrating AI-driven adaptability in future campaigns.
📊 Organizations will shift toward zero-trust policies for code execution environments to counter these threats.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon