North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware

North Korean threat actors are leveraging the 'tasks.json' file in VS Code to automatically trigger StoatWaffle malware when a project is opened. This campaign specifically targets tech professionals through sophisticated fake recruitment processes.
The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that's distributed via malicious Microsoft Visual Studio Code (VS Code) projects. The use of VS Code 'tasks.json' to distribute malware is a relatively new tactic adopted by the threat actor since December 2025, with the attacks leveraging the 'runOn: folderOpen' option to automatically trigger its execution every time any file in the project folder is opened in VS Code. StoatWaffle is a modular malware implemented by Node.js, featuring Stealer and RAT modules. The threat actors achieve initial access through convincingly staged recruitment processes, targeting senior engineers and founders in the crypto sector. In response, Microsoft has updated VS Code to include a mitigation that disables automatic tasks by default and introduces secondary warnings for auto-run tasks.
Source: The Hacker News















