s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.stoatwaffle

📛 Threat Title

Malware family: StoatWaffle

Category: StoatWaffle First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.stoatwaffle`. Printable name: StoatWaffle.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.stoatwaffle VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.stoatwaffle

IOC database

Type
domain
Value
js.stoatwaffle
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.stoatwaffle

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.stoatwaffle

References (1)

Remediations (10)

  • web:blog.redsidesecurity.com

    The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that's distributed via malicious Microsoft Visual Studio Code (VS Code) projects. The use of VS Code "tasks.json" to distribute malware is a relatively new tactic adopted by the threat actor since December 2025, with the attacks ...

  • web:cybersecuritynews.com

    A North Korea-linked hacking group known as WaterPlum has introduced a dangerous new malware called StoatWaffle , deploying it through compromised Visual Studio Code (VSCode) repositories disguised as legitimate blockchain development projects to silently infiltrate developer machines. WaterPlum has been running a campaign known as "Contagious Interview" for some time, drawing victims in ...

  • web:cyberwarzone.com

    A North Korean threat actor, tracked as WaterPlum, is using malicious Visual Studio Code projects to distribute a new malware family called StoatWaffle . The campaign leverages a feature in VS Code to automatically execute code when a project is opened.

  • web:gbhackers.com

    A North Korea-linked threat group known as WaterPlum has introduced a new malware strain called " StoatWaffle " as part of its ongoing Contagious Interview campaign.

  • web:hacklido.com

    North Korean Hackers Deploy StoatWaffle Malware Through Malicious VS Code Projects The North Korean threat actors behind the Contagious Interview campaign, also known as WaterPlum, have been linked to a malware family called StoatWaffle , which is being distributed through malicious Microsoft Visual Studio Code (VS Code) projects.

  • web:malwaretips.com

    The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that's distributed via malicious Microsoft Visual Studio Code (VS Code) projects. The use of VS Code "tasks.json" to distribute malware is a relatively new tactic adopted by the threat actor since December 2025, with the attacks ...

  • web:securityarsenal.com

    Learn how North Korean threat actors abuse VS Code tasks to deploy StoatWaffle and steps to secure your development environment.

  • web:thehackernews.com

    North Korean hackers exploit VS Code tasks.json auto-run since Dec 2025 to deploy StoatWaffle malware , stealing data and enabling remote control.

  • web:vpncentral.com

    North Korean threat actors have started abusing Visual Studio Code auto-run tasks to infect developers with a malware family called StoatWaffle , according to new research. The activity links back to the broader Contagious Interview campaign, where attackers pose as recruiters and send fake coding tests or project files to developers, founders, and senior engineers. Microsoft […]

  • web:www.csoonline.com

    The newly observed malware abuses VS Code's "runOn:folderOpen" feature to execute automatically from trusted projects, enabling near-frictionless compromise.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.