North Korea-linked threat actors abuse VS Code auto-run to spread StoatWaffle malware
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。好的,首先我需要仔细阅读这篇文章,了解它的主要内容。 文章讲的是朝鲜相关的威胁行为者利用VS Code的自动运行任务来传播名为StoatWaffle的恶意软件。他们通过恶意项目在打开文件夹时执行代码,下载网络上的有效载荷,这种方法隐蔽且有效。 接下来,文章提到Team 8是背后的团队,他们在“Contagious Interview”活动中主要使用OtterCookie恶意软件,但自2025年底开始转向StoatWaffle。他们用区块链相关的项目作为诱饵,恶意仓库包含.vscode目录和tasks.json文件。当用户用VS Code打开这个恶意仓库时,就会执行任务文件中的代码。 StoatWaffle恶意软件使用多阶段感染链,首先是一个Node.js加载器连接到C2服务器执行代码,然后下载更多模块。其中一个模块是窃取器,收集浏览器凭证、扩展数据、安装软件细节甚至macOS钥匙串数据,并上传到C2服务器。另一个模块是远程访问木马(RAT),允许攻击者在受感染系统上运行命令并接收结果。 总的来说,StoatWaffle使攻击者能够完全窃取数据并远程控制设备。报告建议关注这些活动的发展。 现在我需要将这些信息浓缩到100字以内。首先确定关键点:朝鲜相关威胁行为者利用VS Code的自动运行任务传播StoatWaffle恶意软件;通过恶意项目在打开文件夹时执行代码;该恶意软件具有窃取器和RAT模块;能够跨操作系统传播;隐蔽且有效。 可能的总结:“朝鲜相关威胁行为者利用VS Code自动运行任务传播StoatWaffle恶意软件。该恶意软件通过区块链项目诱饵传播,在打开文件夹时自动执行任务文件中的代码,下载有效载荷并跨操作系统传播。其功能包括窃取浏览器凭证、扩展数据、软件信息及macOS钥匙串数据,并具备远程控制能力。” 检查字数:大约100字左右。确保没有使用“文章内容总结”等开头,并且涵盖主要信息。 </think> 朝鲜相关威胁行为者利用VS Code自动运行任务传播StoatWaffle恶意软件。该恶意软件通过区块链项目诱饵传播,在打开文件夹时自动执行任务文件中的代码,下载有效载荷并跨操作系统传播。其功能包括窃取浏览器凭证、扩展数据、软件信息及macOS钥匙串数据,并具备远程控制能力。 2026-3-24 07:9:45 Author: securityaffairs.com(查看原文) 阅读量:8 收藏

North Korea-linked threat actors abuse VS Code auto-run to spread StoatWaffle malware

North Korea-linked threat actors use VS Code auto-run tasks to spread StoatWaffle malware via malicious projects that execute on folder open.

North Korea-linked threat actor Team 8 behind the Contagious Interview campaign is spreading StoatWaffle malware through malicious Microsoft Visual Studio Code projects. Since late 2025, they have abused the “tasks.json” auto-run feature in Microsoft Visual Studio Code to execute code whenever a folder is opened, downloading payloads from the web across operating systems, making this tactic both stealthy and effective.

“In Contagious Interview campaign, Team 8 has been mainly using OtterCookie. Starting around December 2025, Team 8 started using new malware. We named this malware StoatWaffle.” reads the report published by NTT Security. “Team 8 leverages a project related to blockchain as a decoy. This malicious repository contains .vscode directory that contains tasks.json file. If a user opens and trusts this malicious reporitory with VSCode, it reads this tasks.json file.”

The task downloads payloads from Vercel and runs them via cmd.exe, starting with a simple downloader. It then installs Node.js if missing and fetches additional files, enabling further malware execution across operating systems.

The StoatWaffle malware uses a multi-stage infection chain. It begins with a Node.js loader that repeatedly connects to a command-and-control (C2) server and executes any code it receives. A second downloader is then deployed, continuing this communication and quickly delivering additional malware modules.

One module acts as a stealer, collecting credentials from browsers, extension data, installed software details, and even macOS Keychain data, then sending everything back to the attacker. It can also access Windows data through WSL environments.

“Stealer module thefts credentials stored on Web browsers and designated browser extension data and uploads them to C2 server. If the victim browser was Chromium family, it steals browser extension data (Appendix) besides stored credentials. If the victim browser was Firefox, it steals browser extension data besides stored credentials. It reads extensions.json and gets the list of browser extension names, then checks whether designated keyword is included.” continues the report. “If the victim OS was macOS, it also steals Keychain database.”

Another module works as a remote access trojan (RAT), allowing attackers to run commands on the infected system and receive results. Overall, the malware enables full data theft and remote control of compromised devices.

“StoatWaffle is a modular malware implemeted by Node.js and it has Stealer and RAT modules. WaterPlum is continuously developing new malware and updating existing ones. We think it necessary to pay close attention to their activities.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, StoatWaffle)




文章来源: https://securityaffairs.com/189880/security/north-korea-linked-threat-actors-abuse-vs-code-auto-run-to-spread-stoatwaffle-malware.html
如有侵权请联系:admin#unsafe.sh