Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO

North Korean Hackers Exploit VS Code to Deploy StoatWaffle

1 reports · First detected 2026-03-25 · Last active 2026-03-25

Blockchain developers remain prime targets for advanced persistent threat groups because their work routinely involves opening unfamiliar repositories and running third-party code. The latest campaign turns that trust-based workflow into an attack vector, using GitHub projects disguised as legitimate blockchain development work and abusing Visual Studio Code’s automatic execution features. The tactic is significant because malicious activity can blend into ordinary software collaboration, reducing the warning signs before a developer opens and approves a workspace.

NTT Security Japan said Team 8, a unit within the North Korea-linked WaterPlum group, has used the technique since December 2025 to deploy malware called StoatWaffle. Once a victim trusts the project workspace in VS Code, embedded malicious instructions can execute automatically and retrieve additional payloads. The infection chain ultimately enables attackers to steal browser data and gain remote-control capabilities, underscoring the continued focus of North Korean threat actors on developers working in the blockchain sector.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)