BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

13 npm Packages Deliver WeaselBiscuit Stealer

  • Threat actors are distributing 13 malicious npm packages that deliver a new, lightweight JavaScript stealer named WeaselBiscuit.
  • The malware shows functional overlaps with BeaverTail and OtterCookie, tools linked to North Korea’s Contagious Interview campaign, but lacks their advanced features like remote access and crypto-draining code.
  • Despite the code similarities, researchers have not found definitive evidence to conclusively attribute this operation to North Korea based on infrastructure or other campaign metadata.

Cybersecurity researchers have uncovered a cluster of 13 npm packages that deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit, according to an analysis by OpenSourceMalware. The new malware family exhibits functional overlaps with two malware strains tied to the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and OtterCookie. “It’s smaller, lighter, and stripped down, with many of the heavier functions removed entirely,” security researcher Paul McCarty (aka 6mile) said.

- Advertisement -

The malicious packages include @biz44/id10-client, @biz44/id12-client, @biz44/id44-client, @biz44/id79-client, @biz44/id95-client, @biz44/id99-client, @biz44/process-runtime-utils, @biz44/runtime-utils, engin1, id79-client, process-lhpm, process-mite, and process-tailwind. BeaverTail is a cross-platform information-stealing malware and downloader used since at least late 2022 to target software developers, IT professionals, and cryptocurrency users. Meanwhile, OtterCookie combines information-stealing capabilities with remote access functionality, allowing operators to execute commands on compromised hosts.

Consequently, WeaselBiscuit stands out for its simplicity, lacking remote access, persistence, crypto wallet-draining code, and secondary payload delivery like InvisibleFerret. Instead, it triggers via an npm import, which prompts the loader (“loader.js”) to fetch the main malware from an Npoint dead drop and execute it directly in memory. Upon execution, it resolves its command-and-control (C2) configuration from a separate Npoint URL, profiles the infected host, and harvests Chrome extension storage across Windows, macOS, and Linux.

Based on operator commands from the C2 server (“103.170.217[.]184:8787”), it can also log clipboard contents and keystrokes on Windows machines. “While this malware does not have the same crypto wallet stealer functions as its big siblings, the Chrome extension-storage capability is financially relevant: it can expose wallet-extension state or other extension-held sensitive data,” McCarty explained. “It uploads every readable, nonempty file under the extension’s Local Extension Settings directory — a raw LevelDB key/value store — wholesale.”

Other tradecraft pointing to North Korea includes using Npoint.io, a lightweight online JSON storage service, and nested public-IP and geolocation lookups via api.ipify.org and ip-api.com. Similarities in C2 architecture overlap with OtterCookie, and the use of a numerical campaign ID (10, 12, 44, 79, 95, 99) mirrors that of PolinRider. However, OpenSourceMalware has emphasized that despite the “meaningful overlap with DPRK-associated Contagious Interview tooling,” there is no definitive evidence in terms of operator infrastructure, victimology, campaign metadata, or signing material to conclusively attribute it to North Korea.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

CleanSpark Ends Monthly Bitcoin Reports, Cites Data Center Growth

CleanSpark produced 529 BTC in September, averaging 17.64 BTC per day, and holds 13,530...

China doc exposes pig butchering scam border horrors

China released a documentary series exposing pig butchering scams across Southeast AsiaNearly 100,000 law...

Qureshi Slams Drake’s ‘Bunker Mode’ as Crypto Doomerism

Dragonfly managing partner Haseeb Qureshi called Ethereum researcher Justin Drake’s “bunker mode” warning “cryptographic...

CISA Adds 5 Flax Typhoon Exploited Flaws to KEV Catalog

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after China-linked threat actor...

Empire Market co-creator gets 40 years for $430M darknet drug sales

Raheim Hamilton, co-creator of darknet marketplace Empire Market, was sentenced to 40 years in...

Must Read

14 Ways On How to Make Money with Cryptocurrency

Many people want to make money with cryptocurrency because they have heard the success stories of people who became millionaires from zero.If you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading