North Korean Hackers Exploit VS Code to Deploy StoatWaffle
Blockchain developers remain prime targets for advanced persistent threat groups because their work routinely involves opening unfamiliar repositories and running third-party code. The latest campaign turns that trust-based workflow into an attack vector, using GitHub projects disguised as legitimate blockchain development work and abusing Visual Studio Code’s automatic execution features. The tactic is significant because malicious activity can blend into ordinary software collaboration, reducing the warning signs before a developer opens and approves a workspace.
NTT Security Japan said Team 8, a unit within the North Korea-linked WaterPlum group, has used the technique since December 2025 to deploy malware called StoatWaffle. Once a victim trusts the project workspace in VS Code, embedded malicious instructions can execute automatically and retrieve additional payloads. The infection chain ultimately enables attackers to steal browser data and gain remote-control capabilities, underscoring the continued focus of North Korean threat actors on developers working in the blockchain sector.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.