StoatWaffle is a modular Node.js malware family combining staged loaders, credential-stealing components, and remote-access trojan functionality. Used since approximately December 2025, it is attributed to the North Korea-linked WaterPlum threat actor, also tracked as Team 8, and associated with the Contagious Interview campaign. It targets software developers and IT professionals, particularly those working in cryptocurrency, blockchain, and Web3.
Delivery uses fraudulent recruitment processes, technical interviews, malicious npm packages, and blockchain-themed Visual Studio Code projects. Malicious project task configurations trigger code execution when victims open and trust a project folder. The infection chain checks for Node.js and installs it if necessary, then runs successive downloaders that poll command-and-control infrastructure and execute received Node.js code to deploy additional modules.
The stealer collects credentials and selected extension data from Chromium-based browsers and Mozilla Firefox, gathers installed-software information, and uploads stolen data to attacker-controlled infrastructure. On macOS, it also targets Keychain databases, including iCloud Keychain data. It can detect Windows Subsystem for Linux and access Windows user data from that environment. The RAT maintains command-and-control communication and supports directory navigation, file enumeration and searching, file uploads, arbitrary shell commands, and Node.js code execution. Its remote-access functionality supports persistent access and pivoting across compromised environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
StoatWaffle Modular Node.js loader, credential harvester and remote-access malware
The malware, dubbed StoatWaffle, has been attributed to a group tracked as WaterPlum, also known as Team 8, Moralis, or the Modilus family. The malware is a modular implant written in Node.js and includes capabilities for stealing credentials and providing remote access to compromised systems.
The malware, dubbed StoatWaffle, has been attributed to a group tracked as WaterPlum, also known as Team 8, Moralis, or the Modilus family. The malware is a modular implant written in Node.js and includes capabilities for stealing credentials and providing remote access to compromised systems.
The malware, dubbed StoatWaffle, has been attributed to a group tracked as WaterPlum, also known as Team 8, Moralis, or the Modilus family. The malware is a modular implant written in Node.js and includes capabilities for stealing credentials and providing remote access to compromised systems.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
WaterPlum actors upload malicious Node Package Manager (NPM) packages embedded with either BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle malware.
StoatWaffle can be hidden inside blockchain-themed projects and use a Visual Studio Code configuration to run code when a victim opens and trusts the folder. The IoC listed is .vscode/tasks.json.
“Other sensitive data targeted for exfiltration includes… Clipboard information, key-logs (recorded keystrokes), screenshots.”
The attackers obtained funds or account credentials from more than 7,000 cryptocurrency wallets... Stolen browser logins, wallet keys... can support further theft.
Targeted data includes “Any files or data of interest to the actors on a PC or in shared folders (ID pictures of driver’s licenses, passports, etc.).”
“Other sensitive data targeted for exfiltration includes… Clipboard information, key-logs (recorded keystrokes), screenshots.”
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family distributed in the WaterPlum campaign, most often hosted in blockchain-themed repositories and delivered through fake job-interview or technical-task scenarios.
A malicious payload delivered in blockchain-themed Visual Studio Code projects. The projects automatically execute code after a victim trusts the folder; the content does not further assign distinct malware capabilities to StoatWaffle.
A malware family used by WaterPlum in its Contagious Interview social-engineering campaign. The campaign targets freelance developers and blockchain/Web3 specialists and supports cryptocurrency theft, credential theft, and potential corporate infiltration.
A malware family used in the Contagious Interview campaign targeting software and cryptocurrency-related professionals.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.