A joint advisory from law enforcement agencies in Japan, the United States, Australia, and Germany has revealed that the North Korean hacking group WaterPlum compromised at least 30,000 devices globally between December 2025 and July 2026. The group is also reported to have transferred over $10.7 million in stolen cryptocurrency to North Korea.
WaterPlum is associated with a multi-year campaign known as "Contagious Interview," which targets job seekers with malicious npm packages designed to infect their devices. The attackers frequently impersonate legitimate companies in the AI, cryptocurrency, and NFT sectors, or leverage recruiting and freelance platforms to approach potential victims. During fake interviews and coding tests, victims are often instructed to download projects, troubleshoot supposed video-conferencing issues, or execute malicious code.
The advisory states that WaterPlum actors have infected devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets. Specifically, 1.7 billion Japanese yen (JPY), equivalent to $10.71 million USD, in cryptocurrency assets were transferred to the Democratic People's Republic of Korea (DPRK).
Several malware families have been linked to WaterPlum operations. These include BeaverTail, a JavaScript malware hidden in npm packages; InvisibleFerret, a Python-based backdoor; OtterCookie, a JavaScript remote-access trojan and information stealer; and OtterCandy, which combines OtterCookie with remote access trojan (RAT) capabilities. Another notable malware is StoatWaffle, a modular Node.js malware delivered through malicious Visual Studio Code projects, which uses configuration files to execute code once a folder is opened and trusted.
Once a system is compromised, the attackers attempt to steal various types of data, including browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents. They also capture screenshots. The access gained from infected computers can be used to pivot into employers' or clients' networks, potentially expanding the attacks to include intellectual property theft and espionage.
Investigators have also directly connected WaterPlum to North Korea's fraudulent IT worker operations. The advisory indicates that some WaterPlum hackers also work as remote IT professionals performing web development for clients, and that both groups have utilized the same IP addresses. Furthermore, North Korean IT workers are believed to reuse identity documents stolen in WaterPlum attacks to impersonate victims and secure jobs. During online interviews, WaterPlum actors have been observed using AI face-swapping software, then turning off their cameras and citing network problems.
The FBI and Japanese police assess that WaterPlum actors and certain North Korean IT workers operate under the country's 313 General Bureau, which is part of the Munitions Industry Department responsible for North Korea's weapons research and production. Japan's National Police Agency reported that authorities identified, investigated, and dismantled a North Korean IT-worker "laptop farm" within Japan for the first time, uncovering evidence of several hundred million yen being transferred abroad.
The advisory recommends that companies meticulously verify the identities, locations, and qualifications of job applicants. It also advises restricting applicant access to only the systems and data necessary for their roles. Developers are urged to avoid running unknown code outside of a sandbox environment and to thoroughly inspect provided files and code for commands that might fetch additional payloads.






