North Korea's most prolific developer-targeting operation has turned the technical job interview into a software supply-chain attack at scale. A joint advisory published on 18 September 2026 by Japan's National Police Agency (NPA) and National Cybersecurity Office (NCO), the FBI, the US Department of Defense Cyber Crime Center (DC3), the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), and Germany's BND and BfV says the group known as WaterPlum, commonly referred to as "Contagious Interview", compromised at least 30,000 PCs in more than 100 countries between around December 2025 and July 2026. It took funds or account credentials from over 7,000 cryptocurrency wallets and moved at least JPY 1.7 billion (USD 10.71 million) in crypto assets to the DPRK. The infection vector is code that developers run themselves: npm packages and Visual Studio Code projects handed over as "coding assignments". Any organisation whose engineers interview externally, take freelance work or hold wallet keys on their workstations is in scope.

Who is WaterPlum?

The NPA and FBI assess that both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, subordinate to the Central Committee of the Workers' Party of Korea. Some WaterPlum actors also work as North Korean IT workers doing web design and development for clients, and the advisory states that WaterPlum actors and IT workers used the same IP addresses when accessing laptop farms, using crowdsourcing services and applying for positions at a Japanese cryptocurrency exchange.

According to the NPA, the primary targets were individual web designers, engineers and specialists in cryptocurrency, blockchain and Web3 technologies. Japanese authorities also, for the first time, identified, investigated and dismantled a "laptop farm" operated by an enabler in Japan, and obtained evidence that the group transferred several hundred million yen in cryptocurrency outside the country. The TTPs were uncovered by the National Cyber Department of the NPA's Kanto Regional Police Bureau, prefectural police and the FBI, with private-sector information sharing; the advisory thanks NTT Security (Japan) KK and bitFlyer, Inc.

Attack mechanics: the coding test is the payload

WaterPlum actors pose as prospective employers, often impersonating legitimate AI, cryptocurrency or NFT companies, and recruit through social media, online job platforms, gig-work platforms and freelance marketplaces. During the hiring cycle they require a technical online interview or a coding assignment, then instruct the candidate to download and execute files hosted on developer collaboration platforms and code repositories, either to complete the assignment or to "troubleshoot an error" in the video-conferencing platform. The malicious code arrives as npm packages embedded with one of five malware families:

Malware familyDescription in the joint advisory
BeaverTailJavaScript-based malware hidden inside npm packages; can be downloaded from GitHub or Bitbucket
InvisibleFerretPython-based backdoor into victims' networks
OtterCookieJavaScript-based remote access trojan and information stealer
OtterCandyCombines the features of OtterCookie and RATatouille
StoatWaffleModular Node.js family combining a loader, credential harvesting and a RAT; uses blockchain-themed repositories with a malicious VS Code configuration that auto-runs when the folder is opened and trusted

Once a loader runs, the actors use RATs to maintain access, persistence and pivot paths, and infostealers to send data and cryptocurrency to a C2 IP address. Targeted data includes browser-stored credentials; clipboard contents, keystrokes and screenshots; wallet private keys and seed phrases; and any files of interest, including ID images such as driver's licences and passports. The agencies stress the downstream risk: stolen credentials can be used against the victim's employer, clients or contracting parties for espionage, IP theft and lateral movement, and stolen ID images let IT workers impersonate victims to earn foreign currency.

The advisory does not publish file hashes, package names, domains or IP addresses, so detection has to rely on behaviour and process control rather than IOC matching.

Interview tradecraft the agencies observed

  • Online interviews conducted with AI face-swapping software; after a few minutes the actors disabled their video and asked the target to do the same, citing network issues.
  • Practising Japanese pronunciation with text-to-speech software, and consistent use of free machine-translation and AI service plans.
  • Taking North Korean holidays off to play games and watch football videos instead of running operations.

The IT-worker side: laptop farms and extortion

The advisory describes a laptop farm as a location, often an enabler's home, where employment-related computers are remotely controlled by North Korean IT workers, who are usually located in North Korea, China or Russia, with a small number in Africa and Southeast Asia. Enablers supply ID images and bank accounts and create VPS infrastructure to hide where the work is done. The agencies note that paying North Korean IT workers may breach domestic law and DPRK sanctions. Beyond revenue generation, one IT worker extorted a company over payment and published its proprietary source code online; another, hired for website maintenance, defaced the client's site and rendered it inaccessible.

In May 2025, a Japanese cryptocurrency exchange received an engineering application from an apparent North Korean IT worker who used a VPN, claimed Malaysian birth and Finnish residence, listed more than ten skills in each of several categories, and could not explain most of them in an English-language interview. The company did not hire the applicant and no damage occurred.

Key figures

MetricFigure (per the advisory)
Activity window measured by NPAAround December 2025 to July 2026
PCs compromisedAt least 30,000, in over 100 countries including Japan and the US
Cryptocurrency wallets affectedOver 7,000
Crypto assets transferred to the DPRKAt least JPY 1.7 billion (USD 10.71 million)
Laptop farms dismantled in JapanFirst ever case

Defensive playbook: developer workstation and supply-chain controls

For engineers and freelancers

  1. Never run a take-home assignment on a machine that holds wallets, credentials or client code. The agencies advise running unknown code only in a sandbox or virtual machine, after checking for obfuscated or unreadable sections.
  2. Open unknown VS Code projects in Restricted Mode. Answer "No" to "Do you trust the author of the files in this folder?", which prevents .vscode/tasks.json from executing on launch. Inspect tasks.json in Restricted Mode or another editor before trusting the folder, and do not open unknown projects inside a path you have previously marked as trusted.
  3. Distrust specific strings. The advisory flags commands or scripts containing curl, base64, -enc, mshta, Invoke-WebRequest -uri, iwr -uri or hidden.
  4. If infected, assume the wallet is gone. Disconnect the device, create a new wallet on a separate device, move all assets, store the new seed phrase offline, back up essential data and fully reinstall the operating system.

Inspect a repository before you open or install it

# Look for auto-run VS Code tasks and the command patterns the advisory flags
find . -path '*/.vscode/*' -name '*.json' -print -exec grep -nE 'folderOpen|curl|base64|-enc|mshta|Invoke-WebRequest|iwr |hidden' {} +

# List npm lifecycle scripts before installing anything
cat package.json | grep -A15 '"scripts"'

# Install dependencies without running lifecycle scripts (does not make running the project safe)
npm install --ignore-scripts

VS Code hardening for managed developer endpoints

{
  "security.workspace.trust.enabled": true,
  "security.workspace.trust.startupPrompt": "always",
  "security.workspace.trust.untrustedFiles": "prompt",
  "task.allowAutomaticTasks": "off"
}

Workspace Trust is what gates the auto-run behaviour StoatWaffle relies on; disabling automatic tasks adds a second barrier even if a user trusts a folder by mistake.

For security teams and hiring managers

  1. Deploy EDR on developer endpoints, as the agencies recommend, and alert when node, python or Code.exe spawn shells that use the flagged strings.
  2. Separate interview and freelance activity from corporate identity. A compromised personal laptop that also holds SSO sessions, cloud keys or source-code tokens turns a candidate's mistake into your incident.
  3. Verify applicants. Check that IP addresses broadly match claimed residence, call listed phone numbers, probe resume skills and certification numbers in detail, ask personal questions, and be wary of bursts of applications, refusals to meet in person, and requests for crypto payment or payment to another person's account.
  4. Limit contractor blast radius. Grant source code, credentials and access on a least-privilege basis, push the same scrutiny down to subcontractors, and revoke accounts and sessions immediately if a contractor is suspected.
  5. Report suspected North Korean IT workers to police or the FBI; the agencies note that knowingly paying them or providing ID images can be a crime.

Endpoint hunting starting point (Microsoft Defender XDR)

// Starting point: developer runtimes spawning shells with strings flagged in the joint advisory
DeviceProcessEvents
| where Timestamp > ago(30d)
| where InitiatingProcessFileName in~ ("node.exe","Code.exe","python.exe")
| where FileName in~ ("cmd.exe","powershell.exe","pwsh.exe","mshta.exe","curl.exe")
| where ProcessCommandLine has_any ("curl","base64","-enc","mshta","Invoke-WebRequest","iwr ","hidden")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, ProcessCommandLine

Why this matters

Seven agencies across four countries putting hard numbers on a single developer-targeting operation is unusual, and WaterPlum's overlap with the IT-worker programme means a single compromised freelancer can become an entry point into every client they touch. The agencies close by warning that the techniques described are "only examples" and that the actors continuously evolve. The durable defences are structural: isolate untrusted code, keep wallets and corporate credentials off machines used for interviews, and treat every repository handed over by a stranger as hostile until proven otherwise.