discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Malware researchers find 13 npm packages delivering a new stealer called WeaselBiscuit, linked to DPRK malware campaigns.

By Ravie Lakshmanan·Sep 18·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Image: thehackernews.com

Security researchers discover a cluster of 13 npm packages that deliver a new JavaScript stealer, WeaselBiscuit, associated with DPRK malware campaigns.

Why it matters

This discovery highlights the threat of cross-platform malware and the need for better npm package security controls.

A new type of malware called WeaselBiscuit has been found. It's like a smaller version of other bad software that spies on computers. It can see what you type and copy, and it can look at your saved passwords in your browser.

Analysis

{"

WeaselBiscuit Stealer Details and Functionality":-13,"WeaselBiscuit":"Similar to DPRK malware like BeaverTail and OtterCookie, but smaller and stripped down.","Functionality":"The malware can also log clipboard contents and keystrokes on Windows machines based on operator commands.","

Comparison with DPRK Malware":-13,"

Npoint.io and API Usage":-13,"Npoint.io":"Uses Npoint.io, a lightweight online JSON storage service, and nested public-IP and geolocation lookups.","

Campaign ID and C2 Architecture":-13,"Campaign ID":"Uses numerical campaign IDs (10, 12, 44, 79, 95, 99) to tag each install, mirroring that of PolinRider.","

Operator Commands and C2 Configuration":-13,"Operator Commands":"Executes commands from a C2 server, such as logging clipboard contents and keystrokes on Windows machines."}

Key points

  • WeaselBiscuit is a new JavaScript stealer delivered via 13 npm packages.
  • It is similar to DPRK malware like BeaverTail and OtterCookie but smaller and stripped down.
  • It can log clipboard contents and keystrokes on Windows machines.
  • It uses Npoint.io and nested public-IP and geolocation lookups.
  • It can be identified by numerical campaign IDs (10, 12, 44, 79, 95, 99).
The Upside

With better security measures, we can stop this type of malware from spreading and causing damage.

The Downside

If this malware is not stopped, it could cause more damage to computers and steal more sensitive information.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwarenpm-packagesnorth-koreachrome-extension-storage

Author

Ravie Lakshmanan

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 18, 2026

Source

thehackernews.com

Share

Topics

securitymalwarenpm-packagesnorth-koreachrome-extension-storage

Related

More from this desk

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.

Oct 7·krebsonsecurity.com

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

Jordanian teenager detained for leading ShinyHunters, a data theft and extortion group. FBI investigating extortion of Boeing subsidiary Jeppesen ForeFlight.

Oct 7·schneier.com

Apple’s Verified Photography System

Apple introduces a new system called 'Reference Image' to verify iPhone photos without tying them to specific devices or photographers.