INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

North Korean Hackers Deploy StoatWaffle Malware via VS Code Tasks

| 2026-03-23 18:09 CRITICAL HIGH
Executive Summary AI-generated
The US Department of Justice has announced the sentencing of three men - Audricus Phagnasay, Jason Salazar, and Alexander Paul Travis - for their roles in furthering North Korea's fraudulent information technology worker scheme. These individuals have been found guilty of practically giving the keys to the online kingdom to likely North Korean overseas technology workers seeking illicit revenue. The scheme involves a complex network of IT workers from prestigious universities in North Korea who attend an intensive interview process before joining, and those chosen are not junior developers but rather founders, CTOs, and senior engineers with elevated access to company tech infrastructure and cryptocurrency wallets. This is part of a coordinated malware campaign targeting cryptocurrency professionals through LinkedIn social engineering, fake venture capital firms, and fraudulent video conferencing links. The scheme also involves the use of VS Code Auto-Run Tasks to deploy StoatWaffle malware, which has been attributed to North Korean Hackers Abuse VS Code.
Technical Mitigations AI-generated
* Use secure coding practices, such as validating user input and ensuring proper error handling, to prevent the exploitation of vulnerabilities like those found in StoatWaffle. * Regularly update and patch dependencies, including npm packages, to ensure that known vulnerabilities are addressed before they can be exploited by attackers. * Implement robust access controls, such as multi-factor authentication (MFA) and role-based access control (RBAC), to limit the privileges of developers and prevent unauthorized access to sensitive systems or data. * Use secure coding guidelines and best practices for VS Code projects, including configuring tasks.json to run on folderOpen mode instead of automatic execution when files are opened in VS Code.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Contagious InterviewContagious Interview BeaverTailBeaverTailInvisibleFerretInvisibleFerret
Target & Sectors
DPRK DPRK technologytechnology governmentgovernment
Incident Timeline
November 2025
North Korean hackers used VS Code auto-run tasks to deploy StoatWaffle malware.
organisation Phagnasay and Salazar
financial $2,000 $ fine
financial $193,265 prison
2025-12-21
Threat actors used a VS Code auto-run task to deploy StoatWaffle malware.
infrastructure Vs Code
organisation GitHub
organisation GitLab
organisation Bitbucket
December 2025
Threat actors used VS Code auto-run tasks to deploy StoatWaffle malware.
infrastructure Vs Code
observable tasks.json
organisation FlexibleFerret
organisation OtterCookie
organisation GolangGhost
organisation PylangGhost
threat_actor Contagious Interview
organisation PolinRider
organisation GitLab
organisation Microsoft
organisation GitHub
organisation Tron, Aptos
organisation BSC
infrastructure Macos
organisation Node.js
organisation Stealer
infrastructure Windows
organisation Mozilla Firefox
organisation Neutralinojs
organisation WeaselStore
2026-01-13
Threat actors used VS Code auto-run tasks to deploy StoatWaffle malware.
infrastructure Vs Code
industry Technology
organisation Security Alliance
organisation Notion[.]so
January 2026
Microsoft included a new "task.allowAutomaticTasks" setting in the January 2026 update of VS Code to mitigate North Korean hackers' abuse.
infrastructure Vs Code
observable tasks.json
infrastructure 1.109
general_metric 1.109 version
February 2026
North Korean threat actors used VS Code auto-run tasks to deploy StoatWaffle malware.
infrastructure 1.110
general_metric 1.110 release
organisation the U.S. Department of Justice (DoJ
organisation Audricus Phagnasay
infrastructure Macos
infrastructure Windows
organisation Workspace Trust
organisation GhostCall
organisation ClickFix
organisation CAPTCHA
organisation Terminal
organisation MacPaw
2026-03-16
North Korean hackers used VS Code auto-run tasks to deploy StoatWaffle malware.
source_region DPRK
target_region Korea, Democratic People's Republic of
organisation IBM
organisation NTT Security
2026-03-23
North Korean-linked hackers target developers via malicious VS Code projects, deploying StoatWaffle malware.
infrastructure Vs Code
infrastructure Visual Studio Code
threat_actor Contagious Interview
organisation Microsoft Visual Studio Code
organisation Deploy StoatWaffle
organisation StoatWaffle
organisation Red Asgard
organisation TsunamiKit
organisation XMRig
organisation the Visual Studio Code
organisation The Hacker News
infrastructure Macos
organisation Node.js
organisation Apple
organisation DPRK
organisation the Democratic People's Republic of Korea
Tactical Metrics
Metrics
infrastructure
​Vs Code
Affected Product
Metrics
infrastructure
​Visual Studio Code
Affected Product
Metrics
infrastructure
​Macos
Affected Product
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​1.109
Software Version
Metrics
infrastructure
​1.110
Software Version
Metrics
financial
2,000
$ Fine
Metrics
financial
193,265
Prison
Intelligence Sources