BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

13 npm Packages Deliver WeaselBiscuit Stealer

  • Threat actors are distributing 13 malicious npm packages that deliver a new, lightweight JavaScript stealer named WeaselBiscuit.
  • The malware shows functional overlaps with BeaverTail and OtterCookie, tools linked to North Korea’s Contagious Interview campaign, but lacks their advanced features like remote access and crypto-draining code.
  • Despite the code similarities, researchers have not found definitive evidence to conclusively attribute this operation to North Korea based on infrastructure or other campaign metadata.

Cybersecurity researchers have uncovered a cluster of 13 npm packages that deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit, according to an analysis by OpenSourceMalware. The new malware family exhibits functional overlaps with two malware strains tied to the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and OtterCookie. “It’s smaller, lighter, and stripped down, with many of the heavier functions removed entirely,” security researcher Paul McCarty (aka 6mile) said.

- Advertisement -

The malicious packages include @biz44/id10-client, @biz44/id12-client, @biz44/id44-client, @biz44/id79-client, @biz44/id95-client, @biz44/id99-client, @biz44/process-runtime-utils, @biz44/runtime-utils, engin1, id79-client, process-lhpm, process-mite, and process-tailwind. BeaverTail is a cross-platform information-stealing malware and downloader used since at least late 2022 to target software developers, IT professionals, and cryptocurrency users. Meanwhile, OtterCookie combines information-stealing capabilities with remote access functionality, allowing operators to execute commands on compromised hosts.

Consequently, WeaselBiscuit stands out for its simplicity, lacking remote access, persistence, crypto wallet-draining code, and secondary payload delivery like InvisibleFerret. Instead, it triggers via an npm import, which prompts the loader (“loader.js”) to fetch the main malware from an Npoint dead drop and execute it directly in memory. Upon execution, it resolves its command-and-control (C2) configuration from a separate Npoint URL, profiles the infected host, and harvests Chrome extension storage across Windows, macOS, and Linux.

Based on operator commands from the C2 server (“103.170.217[.]184:8787”), it can also log clipboard contents and keystrokes on Windows machines. “While this malware does not have the same crypto wallet stealer functions as its big siblings, the Chrome extension-storage capability is financially relevant: it can expose wallet-extension state or other extension-held sensitive data,” McCarty explained. “It uploads every readable, nonempty file under the extension’s Local Extension Settings directory — a raw LevelDB key/value store — wholesale.”

Other tradecraft pointing to North Korea includes using Npoint.io, a lightweight online JSON storage service, and nested public-IP and geolocation lookups via api.ipify.org and ip-api.com. Similarities in C2 architecture overlap with OtterCookie, and the use of a numerical campaign ID (10, 12, 44, 79, 95, 99) mirrors that of PolinRider. However, OpenSourceMalware has emphasized that despite the “meaningful overlap with DPRK-associated Contagious Interview tooling,” there is no definitive evidence in terms of operator infrastructure, victimology, campaign metadata, or signing material to conclusively attribute it to North Korea.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SpaceX 2027 target $217, $10K could grow 40%

Wall Street analysts set a median SpaceX stock price target of $217 by 2027,...

Crypto trail reveals $7M laundering ring tied to contract killings

A Swedish national wanted under an Interpol Red Notice was arrested in the UAE,...

Binance silent on Lagarde claim, vows EU crypto license

Binance declined to comment on reports that European Central Bank President Christine Lagarde intervened...

China-Linked RatHat Android Malware Uses AI to Steal Data

Researchers have uncovered a new Android malware called RatHat, linked to China-based threat actors,...

Bitcoin Could Hit $1.5M If Market Cap Equals Gold: JPMorgan

JPMorgan analysts, led by Nikolaos Panigirtzoglou, say Bitcoin could outperform Gold if ETF hedging...

Must Read

7 Best Crypto To Invest In This Year

Investing in cryptocurrencies has become a popular way for people to diversify their investment portfolio and make potential profits.However, with so many cryptocurrencies available...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading