WaterPlum actors pose as recruiters and use fake technical interviews to trick developers into running malicious code.
The group has infected over 30,000 devices in 100-plus countries and compromised 7,000-plus crypto wallets, transferring roughly $10.71 million to North Korea.
Malicious npm packages and VS Code projects deliver BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle malware.
Successful infections enable credential theft, wallet drains, and lateral movement into employer and client networks.
A joint advisory from agencies in Japan, the United States, Australia, and Germany warns about a North Korean threat group. Investigators call it the WaterPlum cyber actor group, also known as Contagious Interview.
The advisory says WaterPlum actors pose as employers to target software developers and IT professionals. They often impersonate AI, cryptocurrency, and NFT companies to build trust with victims.
The campaign has already infected more than 30,000 devices across over 100 countries. Attackers have stolen funds or credentials from over 7,000 cryptocurrency wallets.
How the fake interview attack works
WaterPlum actors contact targets through job boards, gig platforms, freelance marketplaces, and social media. They pose as hiring managers for AI, blockchain, or NFT startups.
During the interview process, they ask candidates to complete a coding task or fix a bug. The task requires downloading files from a code repository or npm package.
Those files carry hidden malware. Once a victim runs them, the attackers gain a foothold on the device.
Malware capabilities observed in this campaign include:
Credential harvesting from browsers and saved sessions
Clipboard monitoring and keystroke logging
Screenshot capture and file exfiltration
Cryptocurrency wallet targeting, including private keys and seed phrases
Top 10 Cybersecurity Challenges for Enterprises
Top ten enterprise cybersecurity challenges and mitigation strategies for 2026.
The malware families behind the campaign
The advisory names five distinct npm-delivered malware families tied to this campaign. Each plays a different role in the intrusion chain.
Malware
Type
Primary Function
BeaverTail
JavaScript loader
Initial infection via npm packages
InvisibleFerret
Python backdoor
Persistent remote access
OtterCookie
JavaScript RAT/infostealer
Data and credential theft
OtterCandy
Combined RAT
Combines remote access and infostealer capabilities into a single payload
StoatWaffle
Modular Node.js malware
Loader, credential harvesting, and lateral pivoting via VS Code
StoatWaffle stands out for its delivery method. It hides inside blockchain-themed VS Code projects using a hidden .vscode/tasks.json file. The file triggers automatic code execution the moment a developer opens the folder and accepts VS Code’s Workspace Trust prompt. Most developers accept that prompt reflexively without reviewing the task configuration first.
Why this reaches beyond the individual developer
A compromised developer laptop rarely stays a personal problem. Attackers can pivot from a single infected machine into employer and client systems.
The advisory notes that successful infections support espionage and intellectual property theft. Attackers can also move laterally into corporate environments through stolen access.
Strengthening developer endpoint and identity security
Three Hexnode products address different parts of this attack chain: the compromised device, the malicious process, and the access it leads to.
Hexnode UEM – endpoint compliance
Enforces baseline compliance across every platform it supports: Windows, macOS, Linux, iOS/iPadOS, Android, ChromeOS, and visionOS. For developer endpoints specifically, this covers the desktop platforms teams actually code on: Windows, macOS, and Linux.
Flags devices running outdated OS versions as non-compliant, which can then block access to corporate resources through Conditional Access.
Restricts unauthorized app installations
Hexnode XDR – behavioral detection
Investigates suspicious activity on managed Windows and macOS endpoints.
Flags unexpected process behavior tied to a compromised workflow
Supports kill, quarantine, and isolation actions for affected endpoints
Marks a developer workstation as non-compliant the moment XDR detects malware, triggering Hexnode IdP to revoke app access automatically
Complements vendor-specific remediation rather than replacing it
Hexnode IdP – access control
Ties user identity to real-time device posture via Hexnode’s Device Trust Engine before granting access.
Enforces conditional access based on device compliance, not just credentials
Applies role-based access so contractors get only what their role needs
How is WaterPlum different from typical phishing campaigns?
WaterPlum builds a multi-week relationship through fake recruiting before delivering malware. This lowers a victim’s guard compared to a single phishing email.
Can antivirus software catch BeaverTail or InvisibleFerret infections?
Detection varies by variant and update cycle, so antivirus alone isn’t reliable protection. Never run an interview coding test directly on your host machine. Use an isolated container, virtual machine, or sandbox instead, and only connect it to test data, not real credentials or wallets.
What should a developer do after running a suspicious interview task?
Disconnect the device from the network immediately. Assume credentials and wallet data may already be exposed and rotate them from a separate, clean device.
Conclusion
Fake job interviews have become a credible enterprise intrusion path, not just a personal risk for job seekers. Organizations that outsource development work or hire contractors should treat hiring workflows as part of their attack surface.
Security teams should pair developer endpoint hardening with strict controls on code execution during technical assessments. Contractor and freelancer access deserves the same scrutiny as full-time employee access.
Hiring workflows are now an attack surface.
See how Hexnode helps secure developer and contractor endpoints
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.