North Korean WaterPlum Group Infects 30,000 Devices via Malicious npm Packages and Fake Interviews
What Happened — A joint advisory from Japanese, U.S., Australian and German authorities attributes at least 30,000 compromised devices in over 100 countries to the North Korean WaterPlum threat group between December 2025 and July 2026. The actors distributed malicious npm packages (e.g., BeaverTail, StoatWaffle) and used social‑engineered “fake interview” scenarios to trick job seekers into executing malicious code, stealing browser credentials, cryptocurrency wallets and other sensitive data.
Why It Matters for Trust & Control Assurance
- Demonstrates how third‑party code repositories can become a supply‑chain attack vector, testing the effectiveness of continuous vendor‑risk monitoring and evidence collection.
- Highlights the need for security‑awareness programs that cover social‑engineering tactics used in recruiting and freelance platforms.
- Shows that without auditable controls around code‑dependency validation, organizations may lack defensible evidence for audit readiness across multiple frameworks.
Who Is Affected – Technology and SaaS developers, freelance/contracting platforms, recruiting services, and any organization that consumes open‑source JavaScript or Python packages.
Recommended Actions –
- Inventory all npm / PyPI dependencies and map them to a vendor‑risk register.
- Implement automated scanning for malicious code in third‑party packages and enforce a “deny‑by‑default” policy for unsigned modules.
- Augment security‑awareness training with realistic phishing and fake‑interview scenarios.
- Capture and retain evidence of dependency validation and training completion for audit purposes.
Technical Notes – Malware families identified include BeaverTail (JS), InvisibleFerret (Python), OtterCookie/OtterCandy (JS RAT), and StoatWaffle (Node.js). Attack vectors: malicious npm packages (third‑party dependency), social engineering via fake interviews, and credential‑stealing scripts. Source: BleepingComputer