Hiring Tests Used to Breach PCs: North Korea's WaterPlum May Have Infected 30,000+ Devices

  • What happened: On September 18, Japan, the US, Australia and Germany disclosed the methods and scale of WaterPlum, a group that infects PCs through fake recruitment activity.
  • Why it matters: Execution permissions in a development environment can serve as the entry point, and stolen credentials could be used in attacks on the victim's employer.
  • What to watch next: Check the trust settings and execution environment you use when opening coding assignments, and the procedure for cutting off company access if a compromise occurs.

On September 18, 2026, Japan's National Police Agency and the National Cybersecurity Office jointly disclosed the activities of "WaterPlum," an attack group backed by North Korea, together with agencies in the US, Australia and Germany. The group used fake job offers and technical interviews to get developers to run malicious programs, reportedly infecting more than 30,000 PCs across more than 100 countries and regions, including Japan. The activity had been known under the related name "Contagious Interview." The new disclosure adds the scale of damage identified in the investigation and the group's activities within Japan. Applicants open a development environment thinking they are reading a hiring assignment, but which action turns it into a place where the attacker's code runs? The advisory asks both applicants and companies to reconsider exactly where that line falls.

AD

What 30,000 devices, 7,000 wallets and ¥1.7 billion show about the damage

The NPA confirmed infections from around December 2025 through July 2026. The Japanese version of the joint advisory states that, in addition to infections on more than 30,000 PCs, information from more than 7,000 cryptocurrency wallets was stolen. Furthermore, at least about ¥1.7 billion worth of cryptocurrency had been sent to wallets controlled by WaterPlum.

The number of devices, the number of wallets and the transfer amount each count different things. It has not been confirmed that there were 30,000 victims, nor does the advisory say funds were drained from all 7,000 wallets. The ¥1.7 billion, too, is the amount the Japanese version says was sent to the attacker's controlled wallets. These figures cannot be divided to produce an "average loss per victim."

The attackers offer developers what looks like a job opportunity. They pose as recruiters at real AI or cryptocurrency companies, or as staffing services, and make contact through social media or job sites. They then hand over a skills-test assignment or invite the target to an online interview. Under the pretext of completing the assignment or fixing a video-conferencing problem, they get the target to download a program from an external repository and run it.

They also abuse npm, the package-management system used in JavaScript development. The advisory names several pieces of malware, including BeaverTail and InvisibleFerret, but WaterPlum itself is the name of the attack group. Even when the entry point is a hiring assignment, once inside, information-stealing programs and remote-access programs run on the machine. When the interview is over, access to the device does not necessarily end.

VS Code: where "reading" ends and "running" begins

In its analysis of StoatWaffle, published March 17, 2026, NTT Security Japan described repositories disguised as blockchain-related projects. The entry point is the Visual Studio Code (VS Code) configuration file .vscode/tasks.json.

The analyzed example abused a setting called folderOpen, which runs a task when a folder is opened. If the user opens the repository and chooses to trust it, the task downloads and runs an external program. Even someone who only meant to read the assignment's source code may be opening settings that the editor loads and that can contain execution steps.

That said, it would be inaccurate to conclude that "simply opening a folder in VS Code always causes infection." Microsoft's current documentation includes, in addition to whether to trust a workspace, a setting that governs whether automatic tasks are allowed to run. VS Code's Restricted Mode blocks automatic tasks, but trust inherited from a parent folder and permission for automatic tasks must be checked separately.

State when opening the assignment Handling of automatic tasks What applicants should check
Folder not trusted; opened in Restricted Mode Automatic tasks do not run Don't casually switch to trusted while reading the contents
Assignment placed inside an already trusted parent folder Child folders inherit the trust Keep the assignment separate from your usual trusted projects
Trusted, with automatic tasks explicitly disallowed Tasks that run on folder open do not run Even if asked for permission, don't allow it until you've checked the task
Trusted, with automatic tasks allowed Can run automatically when the folder is opened Check the task configuration as well as the assignment code

The table maps the countermeasures in the NPA's September 18 advisory, together with Microsoft's Workspace Trust and automatic task specifications as checked on September 21, onto states of trust and execution permission. Under the current specification, the automatic-task setting defaults to off, but a prompt to allow or disallow appears for workspaces where you haven't yet made a choice. It is better not to treat granting trust and permitting automatic execution as the same decision.

The NPA describes steps for choosing "No" in a warning dialog. Microsoft's current documentation, meanwhile, describes new folders opening in Restricted Mode with a banner showing the state. Screens may not be identical, so rather than relying on whether a dialog appears, confirm that the folder has actually opened in Restricted Mode. If you previously trusted a parent folder, that decision may carry over.

This table is for checking your current settings; it does not reproduce past infected environments. Nor has it been announced that all 30,000 devices were infected via VS Code.

The method of isolation also needs care. NTT's analysis found that StoatWaffle identifies WSL environments (which run Linux on Windows) and also accesses data on the Windows side. Simply running an assignment in WSL does not separate it from your normal Windows environment. Suppressing execution through Restricted Mode and isolating the environment where code runs are separate countermeasures and must be considered as such.

AD

Stolen information can flow to employers and to the next hiring attempt

The information WaterPlum targets includes IDs and passwords saved in browsers, as well as the private keys and seed phrases used to manage cryptocurrency. Images of ID documents and files in shared folders are also targeted. If a remote-access trojan (RAT) maintains its connection, the attacker may retain the ability to use the device after the initial theft.

From there, the damage can reach companies. The joint advisory cites the possibility that stolen credentials could be used to break into the victim's employer or business partners, leading to theft of confidential information or extortion. It adds that ID images could be used by North Korean IT workers to impersonate other people and obtain jobs. Information stored on an applicant's personal device thus becomes material for getting into another organization.

The announcement also contains information linking the side that targets developers with fake job offers to the side that applies to companies under false identities. The NPA explains that IP addresses used by WaterPlum attackers matched IP addresses North Korean IT workers used to connect to laptop farms and freelance-work services. They also matched an IP address used to apply for a job at the Japanese cryptocurrency exchange bitFlyer.

A laptop farm is a base where PCs are placed at the homes of supporters in Japan and elsewhere and remotely operated by North Korean IT workers. The NPA announced that it had identified one in Japan for the first time, and had investigated and dismantled it. The NPA and the FBI assess that WaterPlum and some North Korean IT workers operate under the direction of the 313th General Bureau of the Munitions Industry Department of the Workers' Party of Korea Central Committee. However, matching IP addresses do not allow all attackers and applicants to be treated as the same individuals.

The bitFlyer case involved an application for an engineer position in May 2025. The company noticed suspicious points about the applicant and responded appropriately, so neither a hire nor damage resulted. The entry point to guard differs between developers lured by fake job offers and companies about to accept fake applicants. That the two have been linked makes clearer that hiring departments and IT departments are looking at the same threat from opposite sides.

Protect applicants' devices and company privileges separately

The NPA urges people not to carelessly run third-party code on PCs used for work, cryptocurrency or personal information. When running it is necessary, use a sandbox such as a virtual machine, and check in advance for obfuscated sections or processing you don't understand. In VS Code, inspect the contents in Restricted Mode and include .vscode/tasks.json among the files you check. The advisory also recommends not disabling the Workspace Trust feature.

The moment a recruiter says "change this setting and the assignment will run" is exactly when checks are easiest to skip, because the action needed to proceed with the assessment doubles as permission to run a program. Companies that hand out hiring assignments also have room to prepare procedures that applicants can follow without loosening the protection settings on their work PCs.

After an infection is suspected, deleting the assignment folder is not enough. The NPA recommends cutting off external communication and, from a separate PC, creating a new wallet and moving assets to it. Even if antivirus software removes the malware, information may already have been stolen, or other malware may remain. It also recommends backing up necessary data and then reinstalling the PC's system.

For companies, the NPA calls for limiting the information and access privileges given to contractors to the minimum necessary, and for promptly disabling accounts and sessions once someone is identified as suspicious. If a company tries to defend itself only by spotting bad applicants, it will have granted broad access if it fails to catch one.

Decide in advance where the content of an assignment will be read, in which environment it will be run, and what privileges it will be given at the time of handover. If those steps can be built into both hiring and development, the safety of a device and an employer no longer rests on a single decision by an applicant trying to land a job.