At least 30,000 devices in more than 100 countries were infected and JPY1.7bn (about $10.7m) in cryptocurrency was moved to North Korea, according to a joint advisory from several national law-enforcement and intelligence agencies.
Scope of the campaign: agencies, timeframe, and financial toll
Japan’s National Police Agency (NPA) and National Cybersecurity Office, the FBI, the Defense Department’s Cyber Crime Center, Australia’s ACSC and Germany’s BND and BfV jointly warned that the activity ran from around December 2025 to July 2026. The advisory attributes infections on at least 30,000 devices across over 100 countries and says attackers took funds or credentials from more than 7,000 cryptocurrency wallets. At least JPY1.7bn — reported in the advisory as roughly $10.7m — was transferred to North Korea during the campaign.
The agencies assessed that the group known as WaterPlum, commonly referred to in reporting as Contagious Interview, operates closely with North Korean IT worker networks and that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau, which the advisory describes as part of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.
Recruitment method: fake job interviews and seeded developer packages
The advisory describes a social-engineering pattern built around job recruiting. WaterPlum actors posed as employers — often impersonating AI, cryptocurrency or NFT companies — and recruited developers through social media, job boards and freelance marketplaces. The primary targets were web designers, engineers and specialists in cryptocurrency and Web3.
During technical interviews and coding assignments, victims were instructed to download and run files hosted on developer platforms and code repositories. The actors seeded malicious NPM packages that the advisory names explicitly: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. The advisory highlights StoatWaffle’s delivery inside blockchain-themed Visual Studio Code (VSC) projects; those projects can run code automatically once a victim trusts the folder.
As a defensive detail, the agencies advised opening unknown projects in Restricted Mode and checking any tasks.json file before running project tasks.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTools and effects: remote access trojans, infostealers, and enterprise intrusion
Once a target ran the supplied code, the advisory says, operators used remote access trojans and infostealers to harvest browser credentials, keystrokes, screenshots, wallet private keys and seed phrases, and identity documents. Compromise of an individual’s machine also gave adversaries a path into the victims’ employers, increasing the campaign’s downstream impact beyond direct wallet theft.
Beyond theft, the advisory records destructive and coercive behavior by some workers connected to the scheme: one worker extorted a company over payment and published its source code; another defaced a client’s website and took it offline.
Link to North Korean IT worker networks and laptop farms
The advisory ties WaterPlum tightly to North Korea’s IT worker scheme. It reports that some WaterPlum actors also work as North Korean IT workers and used the same IP addresses to reach laptop farms and crowdsourcing services and to apply for jobs at a Japanese cryptocurrency exchange.
It defines laptop farms as sites — often an enabler’s home — where employment computers are set up and controlled remotely by North Korean workers. Enablers supply identity documents, bank accounts and virtual private servers to obfuscate workers’ locations. Japanese authorities identified and dismantled a laptop farm in Japan for the first time, and investigators estimate that North Korean IT workers moved several hundred million yen abroad, including cryptocurrency.
What this means for employers, contractors, and open-source maintainers
- Employers and procurement teams: The agencies urged firms to limit contractors’ access to source code and credentials and to verify applicants’ identities — practical steps cited directly in the advisory to reduce risks from malicious or co-opted contractors.
- Contractors and freelance platforms: The advisory’s account shows how standard hiring workflows — technical interviews, code tests and repository access — were weaponized. Contractors should expect closer scrutiny of identity and access, and platforms should watch for scripted interview tasks that require running unreviewed code.
- Open-source and package maintainers: The campaign directly exploited developer ecosystems by seeding malicious NPM packages. Maintainers and registries are implicated by that vector and by the advisory’s call to be vigilant about packages used in interview and test projects.
The joint advisory lays out a campaign that blended social engineering, developer tooling, and managed work infrastructures to convert routine hiring interactions into a global theft operation. With infections on tens of thousands of machines, more than 7,000 wallets affected and a substantial transfer of funds, the advisory’s named countermeasures — restricting contractor privileges, verifying identities and using Restricted Mode before running unfamiliar VSC projects — are concrete steps rooted in the specific vectors the agencies identified.
https://www.infosecurity-magazine.com/news/north-korean-waterplum-30000/




