TF-MAL-js.stoatwaffle
📛 Threat Title
Malware family: StoatWaffle
Description
ThreatFox malware family `js.stoatwaffle`. Printable name: StoatWaffle.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.stoatwaffle
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.stoatwaffle
IOC database
- Type
- domain
- Value
js.stoatwaffle- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.stoatwaffle
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.stoatwaffle
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.redsidesecurity.com
The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that's distributed via malicious Microsoft Visual Studio Code (VS Code) projects. The use of VS Code "tasks.json" to distribute malware is a relatively new tactic adopted by the threat actor since December 2025, with the attacks ...
-
web:cybersecuritynews.com
A North Korea-linked hacking group known as WaterPlum has introduced a dangerous new malware called StoatWaffle , deploying it through compromised Visual Studio Code (VSCode) repositories disguised as legitimate blockchain development projects to silently infiltrate developer machines. WaterPlum has been running a campaign known as "Contagious Interview" for some time, drawing victims in ...
-
web:cyberwarzone.com
A North Korean threat actor, tracked as WaterPlum, is using malicious Visual Studio Code projects to distribute a new malware family called StoatWaffle . The campaign leverages a feature in VS Code to automatically execute code when a project is opened.
-
web:gbhackers.com
A North Korea-linked threat group known as WaterPlum has introduced a new malware strain called " StoatWaffle " as part of its ongoing Contagious Interview campaign.
-
web:hacklido.com
North Korean Hackers Deploy StoatWaffle Malware Through Malicious VS Code Projects The North Korean threat actors behind the Contagious Interview campaign, also known as WaterPlum, have been linked to a malware family called StoatWaffle , which is being distributed through malicious Microsoft Visual Studio Code (VS Code) projects.
-
web:malwaretips.com
The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that's distributed via malicious Microsoft Visual Studio Code (VS Code) projects. The use of VS Code "tasks.json" to distribute malware is a relatively new tactic adopted by the threat actor since December 2025, with the attacks ...
-
web:securityarsenal.com
Learn how North Korean threat actors abuse VS Code tasks to deploy StoatWaffle and steps to secure your development environment.
-
web:thehackernews.com
North Korean hackers exploit VS Code tasks.json auto-run since Dec 2025 to deploy StoatWaffle malware , stealing data and enabling remote control.
-
web:vpncentral.com
North Korean threat actors have started abusing Visual Studio Code auto-run tasks to infect developers with a malware family called StoatWaffle , according to new research. The activity links back to the broader Contagious Interview campaign, where attackers pose as recruiters and send fake coding tests or project files to developers, founders, and senior engineers. Microsoft […]
-
web:www.csoonline.com
The newly observed malware abuses VS Code's "runOn:folderOpen" feature to execute automatically from trusted projects, enabling near-frictionless compromise.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.