{"id":2971,"date":"2026-09-18T11:33:55","date_gmt":"2026-09-18T11:33:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2971"},"modified":"2026-09-18T11:33:55","modified_gmt":"2026-09-18T11:33:55","slug":"weaselbiscuit-stealer-spreads-via-13-npm-packages-to-harvest-chrome-extension-storage","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2971","title":{"rendered":"WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 18, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhZypkEn_5V1qllBxmH8UMxTPyA9qoXxQtKpBpJlFq2rtHgMM1wnknkyq4Vmmy0NiCHn2IjS0nyvtmiZpJ-vYOd6VxMFBexh_p6GXuq3Cjda-YfjDOUE5u5V5HfBBAQzEm5DLX3jg_ZrIfEBFlpcBod65T3Q0pXVR7vERfitlS6cBHYVG2K7ek5ivweYTRq\/s1700-nu-rw-lo-l85-e365\/npm-chrome.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed <strong>WeaselBiscuit<\/strong>.<\/p>\n<p>The new malware family, per <a href=\"https:\/\/opensourcemalware.com\/blog\/introducing-weaselbiscuit\" target=\"_blank\">OpenSourceMalware<\/a>, exhibits functional overlaps with two malware strains associated with the Democratic People&#8217;s Republic of Korea&#8217;s (DPRK) Contagious Interview campaign: BeaverTail and OtterCookie. \u00abIt&#8217;s smaller, lighter, and stripped down, with many of the heavier functions removed entirely,\u00bb security researcher Paul McCarty (aka 6mile) said.<\/p>\n<p>The <a href=\"https:\/\/opensourcemalware.com\/?search=%23weaselbiscuit\" target=\"_blank\">names of the packages<\/a> are below &#8211;<\/p>\n<ul>\n<li>@biz44\/id10-client<\/li>\n<li>@biz44\/id12-client<\/li>\n<li>@biz44\/id44-client<\/li>\n<li>@biz44\/id79-client<\/li>\n<li>@biz44\/id95-client<\/li>\n<li>@biz44\/id99-client<\/li>\n<li>@biz44\/process-runtime-utils<\/li>\n<li>@biz44\/runtime-utils<\/li>\n<li>engin1<\/li>\n<li>id79-client<\/li>\n<li>process-lhpm<\/li>\n<li>process-mite<\/li>\n<li>process-tailwind<\/li>\n<\/ul>\n<p>\u00abIt&#8217;s a stripped down stealer that borrows several functions from DPRK&#8217;s BeaverTail and OtterCookie, but is much smaller and self-contained,\u00bb Jenn Gile, co-founder of OpenSourceMalware, said in a statement shared with The Hacker News. \u00abHence the &#8216;WeaselBiscuit&#8217; name, because a weasel is smaller than an otter, and we can argue that biscuits are less fancy than cookies.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>BeaverTail is the name assigned to a <a href=\"https:\/\/gitlab-com.gitlab.io\/gl-security\/security-tech-notes\/threat-intelligence-tech-notes\/north-korean-malware-sept-2025\/\" target=\"_blank\">cross-platform information-stealing malware<\/a> and downloader operated by North Korean threat actors behind Contagious Interview to target software developers, IT professionals, and cryptocurrency users. The malware has been active since at least late 2022.<\/p>\n<p>On the other hand, OtterCookie <a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html\" target=\"_blank\">combines information-stealing capabilities with remote access functionality that allows the operators to execute commands on compromised hosts. The malware was first publicly documented by NTT Security Holdings in December 2024.<\/p>\n<p>WeaselBiscuit is notable for its simplicity, lacking remote access, persistence, cryptocurrency wallet-draining code, and the ability to deliver secondary payloads like InvisibleFerret. Instead, it&#8217;s triggered via an npm import, which causes the loader (\u00abloader.js\u00bb) to pull the main malware from an Npoint dead drop and execute it directly in memory.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEigMnR9TVPtZvj3-58QIeeKBXRFFztEERnlS0AQr1Q1g7vUoC1vkAZT1KGQNSNvjcG2e3fY92tOSNwtlTvu6j2JSzqDgsxd0o2gxQLG8Ds_8IsWP5XnkbsHPznbnMgWqKMwUBSIzwN-lWKVZOg1clhyzVXJe5FHiE0u8LI4C6lAkAPqdsKXaAq8P1dlOePK\/s1700-nu-rw-lo-l85-e365\/we.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEigMnR9TVPtZvj3-58QIeeKBXRFFztEERnlS0AQr1Q1g7vUoC1vkAZT1KGQNSNvjcG2e3fY92tOSNwtlTvu6j2JSzqDgsxd0o2gxQLG8Ds_8IsWP5XnkbsHPznbnMgWqKMwUBSIzwN-lWKVZOg1clhyzVXJe5FHiE0u8LI4C6lAkAPqdsKXaAq8P1dlOePK\/s1700-nu-rw-lo-l85-e365\/we.png\" alt=\"\" border=\"0\" data-original-height=\"2442\" data-original-width=\"1920\"\/><\/a><\/div>\n<p>Upon execution, it resolves its command-and-control (C2) configuration from a separate Npoint URL, profiles the compromised host, and harvests Chrome extension storage across Windows, macOS, and Linux. Based on operator commands received from the C2 server (\u00ab103.170.217[.]184:8787\u00bb), it can also log clipboard contents and keystrokes on Windows machines.<\/p>\n<p>\u00abWhile this malware does not have the same crypto wallet stealer functions as its big siblings, the Chrome extension-storage capability is financially relevant: it can expose wallet-extension state or other extension-held sensitive data,\u00bb McCarty explained. \u00abIt uploads every readable, nonempty file under the extension&#8217;s Local Extension Settings directory \u2014 a raw LevelDB key\/value store \u2014 wholesale.\u00bb<\/p>\n<p>OpenSourceMalware has emphasized that despite the \u00abmeaningful overlap with DPRK-associated Contagious Interview tooling,\u00bb there is no definitive evidence in terms of operator infrastructure, victimology, campaign metadata, or signing material to conclusively attribute it to North Korea.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Other tradecraft signals that point to North Korea are as follows &#8211;<\/p>\n<ul>\n<li>The use of Npoint.io, a lightweight online JSON storage service, an aspect that was flagged by NVISO in November 2025 in connection with Contagious Interview<\/li>\n<li>The use of nested public-IP and geolocation lookup via api.ipify.org and ip-api.com<\/li>\n<li>Similarities in C2 architecture that overlap with OtterCookie<\/li>\n<li>The use of a numerical campaign ID (10, 12, 44, 79, 95, 99) to tag each install, mirroring that of PolinRider<\/li>\n<\/ul>\n<p>If WeaselBiscuit does turn out to be the latest addition to DPRK&#8217;s malware arsenal, this wouldn&#8217;t be the first time the threat actors have attempted to merge the features of BeaverTail and OtterCookie. In October 2025, Cisco Talos said it identified an npm package named \u00abnode-nvm-ssh\u00bb that \u00abhad characteristics of BeaverTail and of OtterCookie, blurring the distinction between the two.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 18, 2026Malware \/ Web Security Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2972,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[182,520,142,39,35,666,478,2478,3458],"class_list":["post-2971","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-chrome","tag-extension","tag-harvest","tag-npm","tag-packages","tag-spreads","tag-stealer","tag-storage","tag-weaselbiscuit"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2971","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2971"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2971\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2972"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2971"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2971"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2971"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}