Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

North Korean WaterPlum Group Infects 30,000 Devices via Malicious npm Packages and Fake Interviews

WaterPlum compromised at least 30,000 devices worldwide by distributing malicious npm packages and conducting fake‑interview scams. The campaign underscores the need for continuous vendor‑risk monitoring and security‑awareness controls to satisfy audit‑readiness requirements.

LiveThreat™ Intelligence · 📅 September 20, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

North Korean WaterPlum Group Infects 30,000 Devices via Malicious npm Packages and Fake Interviews

What Happened — A joint advisory from Japanese, U.S., Australian and German authorities attributes at least 30,000 compromised devices in over 100 countries to the North Korean WaterPlum threat group between December 2025 and July 2026. The actors distributed malicious npm packages (e.g., BeaverTail, StoatWaffle) and used social‑engineered “fake interview” scenarios to trick job seekers into executing malicious code, stealing browser credentials, cryptocurrency wallets and other sensitive data.

Why It Matters for Trust & Control Assurance

  • Demonstrates how third‑party code repositories can become a supply‑chain attack vector, testing the effectiveness of continuous vendor‑risk monitoring and evidence collection.
  • Highlights the need for security‑awareness programs that cover social‑engineering tactics used in recruiting and freelance platforms.
  • Shows that without auditable controls around code‑dependency validation, organizations may lack defensible evidence for audit readiness across multiple frameworks.

Who Is Affected – Technology and SaaS developers, freelance/contracting platforms, recruiting services, and any organization that consumes open‑source JavaScript or Python packages.

Recommended Actions –

  • Inventory all npm / PyPI dependencies and map them to a vendor‑risk register.
  • Implement automated scanning for malicious code in third‑party packages and enforce a “deny‑by‑default” policy for unsigned modules.
  • Augment security‑awareness training with realistic phishing and fake‑interview scenarios.
  • Capture and retain evidence of dependency validation and training completion for audit purposes.

Technical Notes – Malware families identified include BeaverTail (JS), InvisibleFerret (Python), OtterCookie/OtterCandy (JS RAT), and StoatWaffle (Node.js). Attack vectors: malicious npm packages (third‑party dependency), social engineering via fake interviews, and credential‑stealing scripts. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →