{"id":1835,"date":"2026-09-21T14:55:29","date_gmt":"2026-09-21T09:25:29","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1835"},"modified":"2026-09-22T09:16:14","modified_gmt":"2026-09-22T03:46:14","slug":"waterplum-cyber-actor-targets-developers-via-fake-interviews","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/","title":{"rendered":"WaterPlum Cyber Actor Targets Developers via Fake Interviews"},"content":{"rendered":"<p>A joint advisory from agencies in Japan, the United States, Australia, and Germany warns about a North Korean <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-threat-group\/\">threat group<\/a>. Investigators call it the WaterPlum cyber actor group, also known as Contagious Interview.<\/p>\n<p>The advisory says WaterPlum actors pose as employers to target software developers and IT professionals. They often impersonate AI, cryptocurrency, and NFT companies to build trust with victims.<\/p>\n<p>The campaign has already infected more than <a href=\"https:\/\/www.ic3.gov\/CSA\/2026\/260918.pdf?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=waterplum_cyber_actor\" target=\"_blank\" rel=\"nofollow noopener\">30,000<\/a> devices across over 100 countries. Attackers have stolen funds or credentials from over 7,000 cryptocurrency wallets.<\/p>\n<h2>How the fake interview attack works<\/h2>\n<p>WaterPlum actors contact targets through job boards, gig platforms, freelance marketplaces, and social media. They pose as hiring managers for AI, blockchain, or NFT startups.<\/p>\n<p>During the interview process, they ask candidates to complete a coding task or fix a bug. The task requires downloading files from a code repository or npm package.<\/p>\n<p>Those files carry hidden <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-malware\/\">malware<\/a>. Once a victim runs them, the attackers gain a foothold on the device.<\/p>\n<h3>Malware capabilities observed in this campaign include:<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-a-backdoor-in-cybersecurity\/\">Backdoor<\/a> access and remote command execution<\/li>\n<li>Persistence mechanisms that survive reboots<\/li>\n<li>Credential harvesting from browsers and saved sessions<\/li>\n<li>Clipboard monitoring and keystroke logging<\/li>\n<li>Screenshot capture and file exfiltration<\/li>\n<li>Cryptocurrency wallet targeting, including private keys and seed phrases<\/li>\n<\/ul>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-challenges.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Cybersecurity Challenges for Enterprises<\/h4><p>Top ten enterprise cybersecurity challenges and mitigation strategies for 2026.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-10-cybersecurity-challenges-for-enterprises\/\" aria-label=\"Top 10 Cybersecurity Challenges for Enterprises\"><\/a><\/div><\/div><\/div>\n<h2>The malware families behind the campaign<\/h2>\n<p>The advisory names five distinct npm-delivered <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-a-malware-family\/\">malware families<\/a> tied to this campaign. Each plays a different role in the intrusion chain.<\/p>\n<table style=\"width: 79.6342%; height: 168px;\">\n<thead>\n<tr style=\"height: 24px;\">\n<th style=\"width: 24.4919%; text-align: left; height: 24px;\"><strong>Malware<\/strong><\/th>\n<th style=\"width: 26.4988%; text-align: left; height: 24px;\"><strong>Type<\/strong><\/th>\n<th style=\"width: 47.6882%; text-align: left; height: 24px;\"><strong>Primary Function<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 24px;\">\n<td style=\"width: 24.4919%; height: 24px;\">BeaverTail<\/td>\n<td style=\"width: 26.4988%; height: 24px;\">JavaScript loader<\/td>\n<td style=\"width: 47.6882%; height: 24px;\">Initial infection via npm packages<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 24.4919%; height: 24px;\">InvisibleFerret<\/td>\n<td style=\"width: 26.4988%; height: 24px;\">Python backdoor<\/td>\n<td style=\"width: 47.6882%; height: 24px;\">Persistent remote access<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 24.4919%; height: 24px;\">OtterCookie<\/td>\n<td style=\"width: 26.4988%; height: 24px;\">JavaScript RAT\/infostealer<\/td>\n<td style=\"width: 47.6882%; height: 24px;\">Data and credential theft<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 24.4919%; height: 24px;\">OtterCandy<\/td>\n<td style=\"width: 26.4988%; height: 24px;\">Combined RAT<\/td>\n<td style=\"width: 47.6882%; height: 24px;\">Combines remote access and infostealer capabilities into a single payload<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"width: 24.4919%; height: 48px;\">StoatWaffle<\/td>\n<td style=\"width: 26.4988%; height: 48px;\">Modular Node.js malware<\/td>\n<td style=\"width: 47.6882%; height: 48px;\">Loader, credential harvesting, and lateral pivoting via VS Code<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>StoatWaffle stands out for its delivery method. It hides inside blockchain-themed VS Code projects using a hidden <code>.vscode\/tasks.json<\/code> file. The file triggers automatic code execution the moment a developer opens the folder and accepts VS Code&#8217;s Workspace Trust prompt. Most developers accept that prompt reflexively without reviewing the task configuration first.<\/p>\n<h2>Why this reaches beyond the individual developer<\/h2>\n<p>A compromised developer laptop rarely stays a personal problem. Attackers can pivot from a single infected machine into employer and client systems.<\/p>\n<p>The advisory notes that successful infections support espionage and intellectual property theft. Attackers can also move laterally into corporate environments through stolen access.<\/p>\n<h3>Data at risk extends well beyond crypto wallets:<\/h3>\n<ul>\n<li>Browser-stored authentication credentials<\/li>\n<li>Repository access tokens and source code<\/li>\n<li>Corporate VPN or <a href=\"https:\/\/www.hexnode.com\/blogs\/single-sign-on-its-relevance\/\">SSO<\/a> session data<\/li>\n<li>Personal ID documents used for impersonation<\/li>\n<\/ul>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download this cybersecurity kit for blueprints, frameworks, checklists, policy templates, and UEM guidance for enterprises.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Strengthening developer endpoint and identity security<\/h2>\n<p>Three Hexnode products address different parts of this attack chain: the compromised device, the malicious process, and the access it leads to.<\/p>\n<h3>Hexnode UEM &#8211; endpoint compliance<\/h3>\n<p>Enforces baseline compliance across every platform it supports: Windows, macOS, Linux, iOS\/iPadOS, Android, ChromeOS, and visionOS. For developer endpoints specifically, this covers the desktop platforms teams actually code on: Windows, macOS, and Linux.<\/p>\n<ul>\n<li>Flags devices running outdated OS versions as non-compliant, which can then block access to corporate resources through Conditional Access.<\/li>\n<li>Restricts unauthorized app installations<\/li>\n<\/ul>\n<h3>Hexnode XDR &#8211; behavioral detection<\/h3>\n<p>Investigates suspicious activity on managed Windows and macOS endpoints.<\/p>\n<ul>\n<li>Flags unexpected process behavior tied to a compromised workflow<\/li>\n<li>Supports kill, quarantine, and isolation actions for affected endpoints<\/li>\n<li>Marks a developer workstation as non-compliant the moment XDR detects malware, triggering Hexnode IdP to revoke app access automatically<\/li>\n<li>Complements vendor-specific remediation rather than replacing it<\/li>\n<\/ul>\n<h3>Hexnode IdP &#8211; access control<\/h3>\n<p>Ties user identity to real-time device posture via Hexnode&#8217;s Device Trust Engine before granting access.<\/p>\n<ul>\n<li>Enforces conditional access based on device compliance, not just credentials<\/li>\n<li>Applies role-based access so contractors get only what their role needs<\/li>\n<li>Requires step-up <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-multi-factor-authentication-mfa\/\">MFA<\/a> for high-risk actions.<\/li>\n<li>Automates offboarding through SCIM when a contract ends<\/li>\n<\/ul>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How is WaterPlum different from typical phishing campaigns?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>WaterPlum builds a multi-week relationship through fake recruiting before delivering malware. This lowers a victim&#8217;s guard compared to a single phishing email.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can antivirus software catch BeaverTail or InvisibleFerret infections?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Detection varies by variant and update cycle, so antivirus alone isn&#8217;t reliable protection. Never run an interview coding test directly on your host machine. Use an isolated container, virtual machine, or sandbox instead, and only connect it to test data, not real credentials or wallets.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should a developer do after running a suspicious interview task?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Disconnect the device from the network immediately. Assume credentials and wallet data may already be exposed and rotate them from a separate, clean device.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/p>\n<h3>Conclusion<\/h3>\n<p>Fake job interviews have become a credible enterprise intrusion path, not just a personal risk for job seekers. Organizations that outsource development work or hire contractors should treat hiring workflows as part of their attack surface.<\/p>\n<p>Security teams should pair developer endpoint hardening with strict controls on code execution during technical assessments. Contractor and freelancer access deserves the same scrutiny as full-time employee access.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Hiring workflows are now an attack surface. <\/h5><p>See how Hexnode helps secure developer and contractor endpoints<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A joint advisory from agencies in Japan, the United States, Australia, and Germany warns about&#8230;<\/p>\n","protected":false},"author":5,"featured_media":1848,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,15],"class_list":["post-1835","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-malware","product_category-extended-detection-and-response","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>WaterPlum Cyber Actor: North Korean Job Lures Hit Developers<\/title>\n<meta name=\"description\" content=\"WaterPlum cyber actor group uses fake job interviews and malicious npm packages to compromise developers worldwide, per new advisory.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WaterPlum Cyber Actor: North Korean Job Lures Hit Developers\" \/>\n<meta property=\"og:description\" content=\"WaterPlum cyber actor group uses fake job interviews and malicious npm packages to compromise developers worldwide, per new advisory.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-21T09:25:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-22T03:46:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/waterplum-cyber-actor.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"WaterPlum Cyber Actor Targets Developers via Fake Interviews\",\"datePublished\":\"2026-09-21T09:25:29+00:00\",\"dateModified\":\"2026-09-22T03:46:14+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/\"},\"wordCount\":887,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/waterplum-cyber-actor.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/\",\"name\":\"WaterPlum Cyber Actor: North Korean Job Lures Hit Developers\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/waterplum-cyber-actor.jpeg?format=webp\",\"datePublished\":\"2026-09-21T09:25:29+00:00\",\"dateModified\":\"2026-09-22T03:46:14+00:00\",\"description\":\"WaterPlum cyber actor group uses fake job interviews and malicious npm packages to compromise developers worldwide, per new advisory.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/waterplum-cyber-actor.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/waterplum-cyber-actor.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"waterplum cyber actor\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/waterplum-cyber-actor-targets-developers-via-fake-interviews\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WaterPlum Cyber Actor Targets Developers via Fake Interviews\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WaterPlum Cyber Actor: North Korean Job Lures Hit Developers","description":"WaterPlum cyber actor group uses fake job interviews and malicious npm packages to compromise developers worldwide, per new advisory.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/","og_locale":"en_US","og_type":"article","og_title":"WaterPlum Cyber Actor: North Korean Job Lures Hit Developers","og_description":"WaterPlum cyber actor group uses fake job interviews and malicious npm packages to compromise developers worldwide, per new advisory.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-21T09:25:29+00:00","article_modified_time":"2026-09-22T03:46:14+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/waterplum-cyber-actor.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"WaterPlum Cyber Actor Targets Developers via Fake Interviews","datePublished":"2026-09-21T09:25:29+00:00","dateModified":"2026-09-22T03:46:14+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/"},"wordCount":887,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/waterplum-cyber-actor.jpeg?format=webp","articleSection":["Identity Abuse","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/","url":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/","name":"WaterPlum Cyber Actor: North Korean Job Lures Hit Developers","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/waterplum-cyber-actor.jpeg?format=webp","datePublished":"2026-09-21T09:25:29+00:00","dateModified":"2026-09-22T03:46:14+00:00","description":"WaterPlum cyber actor group uses fake job interviews and malicious npm packages to compromise developers worldwide, per new advisory.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/waterplum-cyber-actor.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/waterplum-cyber-actor.jpeg?format=webp","width":1340,"height":700,"caption":"waterplum cyber actor"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/waterplum-cyber-actor-targets-developers-via-fake-interviews\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"WaterPlum Cyber Actor Targets Developers via Fake Interviews"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1835"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1835\/revisions"}],"predecessor-version":[{"id":1863,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1835\/revisions\/1863"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1848"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}