Signal Technology, daily
Sunday, 20 September 2026
← All stories
Security

WaterPlum campaign hits 30,000 devices through fake developer job interviews

North Korea-linked hackers use malicious npm packages and VS Code projects in bogus hiring flows to steal crypto and infiltrate employer networks.

A new joint advisory from Japan, the U.S., Australia, and Germany says North Korea’s WaterPlum group has infected over 30,000 devices in more than 100 countries since December 2025, compromising 7,000+ crypto wallets and routing about $10.7 million in cryptocurrency to the DPRK. The campaign targets software developers and IT workers through fake job postings and interviews, where coding tests, npm packages, and Visual Studio Code projects hide malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Once installed, these tools steal browser credentials, clipboard contents, keystrokes, crypto keys, and documents, and can persist as RATs that remain on the developer’s machine for months. Authorities say WaterPlum overlaps with North Korea’s fraudulent IT worker operations under the 313 General Bureau, with some operators simultaneously working as remote IT staff and reusing IDs stolen in attacks to obtain jobs. The advisory urges companies to rigorously verify remote applicants and tightly scope access, and recommends developers run all interview code in sandboxes or isolated VMs and inspect files carefully for secondary payloads.

Why it matters

For teams that hire developers or work with freelancers, the advisory describes a concrete path from one compromised laptop to stolen crypto, IP theft, or broader network access. WaterPlum targets job seekers with malicious npm packages and Visual Studio Code projects, then uses stolen credentials and remote access to pivot into employers’ or clients’ environments. The group has already infected tens of thousands of devices and moved millions in cryptocurrency to North Korea’s coffers.

Sources