WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Malware researchers find 13 npm packages delivering a new stealer called WeaselBiscuit, linked to DPRK malware campaigns.
Intelligence analysis by Qwen 2.5 (3B)

Security researchers discover a cluster of 13 npm packages that deliver a new JavaScript stealer, WeaselBiscuit, associated with DPRK malware campaigns.
A new type of malware called WeaselBiscuit has been found. It's like a smaller version of other bad software that spies on computers. It can see what you type and copy, and it can look at your saved passwords in your browser.
Analysis
{"
WeaselBiscuit Stealer Details and Functionality":-13,"WeaselBiscuit":"Similar to DPRK malware like BeaverTail and OtterCookie, but smaller and stripped down.","Functionality":"The malware can also log clipboard contents and keystrokes on Windows machines based on operator commands.","
Comparison with DPRK Malware":-13,"
Npoint.io and API Usage":-13,"Npoint.io":"Uses Npoint.io, a lightweight online JSON storage service, and nested public-IP and geolocation lookups.","
Campaign ID and C2 Architecture":-13,"Campaign ID":"Uses numerical campaign IDs (10, 12, 44, 79, 95, 99) to tag each install, mirroring that of PolinRider.","
Operator Commands and C2 Configuration":-13,"Operator Commands":"Executes commands from a C2 server, such as logging clipboard contents and keystrokes on Windows machines."}
Key points
- WeaselBiscuit is a new JavaScript stealer delivered via 13 npm packages.
- It is similar to DPRK malware like BeaverTail and OtterCookie but smaller and stripped down.
- It can log clipboard contents and keystrokes on Windows machines.
- It uses Npoint.io and nested public-IP and geolocation lookups.
- It can be identified by numerical campaign IDs (10, 12, 44, 79, 95, 99).
With better security measures, we can stop this type of malware from spreading and causing damage.
If this malware is not stopped, it could cause more damage to computers and steal more sensitive information.


