A North Korean-linked cyber operation known as WaterPlum infected about 30,000 devices worldwide between September 2025 and May 2026, using compromised developer tools and software packages to reach victims across multiple countries.
How Did WaterPlum Reach 30,000 Devices?
The campaign was linked to a multi-year operation involving compromised developer platforms and packages. The attackers targeted software developers and used trusted development environments as a route into systems.
The campaign affected users globally, with researchers in Japan, Australia and Germany collectively examining the activity. The operation demonstrates how compromising tools used by developers can give attackers a path into a much larger group of downstream users.
How Were Developers Targeted?
WaterPlum used several methods to compromise software developers. These included malicious JavaScript inserted into npm packages, compromised developer tools and other software supply-chain techniques.
The attackers also used social engineering. One method involved impersonating recruiters and approaching developers with supposed job opportunities. Malicious files or code could then be introduced during the recruitment process.
Once a developer environment was compromised, the attackers could gain access to additional systems, source code and other sensitive resources.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
What Malware Was Used?
The operation involved multiple malicious tools designed for different stages of an attack. These included malware used for initial access as well as tools capable of stealing information and maintaining control over compromised systems.
The campaign also involved techniques intended to make malicious activity appear legitimate by placing harmful code inside software packages or developer workflows that victims might otherwise trust.
This approach makes software supply-chain attacks particularly difficult to detect because the initial point of compromise can appear to be a legitimate development resource.
Why Are Supply-Chain Attacks Dangerous?
A compromised developer or software package can provide attackers with access beyond the original victim. Malicious components may spread through software development and distribution processes, potentially reaching organisations and users that never interacted directly with the attackers.
The WaterPlum campaign highlights how developer ecosystems can become an effective route for expanding an intrusion.
Rather than targeting every organisation separately, attackers can focus on software, tools or developers positioned higher in the technology supply chain.
Who Was Behind the Campaign?
The activity was linked to WaterPlum, described as a North Korean IT worker operation. The campaign involved developers working remotely and the use of recruitment-related approaches.
The operation also reflected a broader model in which North Korean-linked IT workers seek employment or access to technology companies while concealing aspects of their identities or locations.
Authorities and cybersecurity researchers have increasingly focused on the risks created when such workers obtain access to company systems, development environments and sensitive information.
What Are Authorities Warning About?
Japanese authorities, including the National Police Agency, warned companies about the risks associated with North Korean IT workers. The concerns include workers obtaining remote positions and gaining access to corporate systems.
The advisory urged companies to carefully verify recruitment information, identities and other employment details when hiring remote technology workers.
Businesses were also advised to strengthen internal controls and monitor access to sensitive systems, particularly where remote developers or contractors are involved.
What Does the WaterPlum Campaign Show?
The infection of around 30,000 devices illustrates how attacks on developers can spread far beyond a single computer or company.
By combining compromised software, developer-focused attacks and social engineering, a threat operation can potentially reach a large number of downstream systems.
The campaign also places renewed attention on software supply-chain security and the need for companies to examine not only their own networks, but also the development tools, packages and remote access arrangements on which their systems depend.
The420 Takeaway: Developers Are the New Entry Point
The WaterPlum campaign shows why software supply-chain security cannot stop at protecting company networks. Developers, third-party packages and remote access can become entry points into much larger systems. Companies should closely verify remote hires, control access to sensitive development environments and scrutinise software dependencies before they become a route for wider compromise.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics