#WeaselBiscuit
The headline made me lmao.

WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials

🤣

#VulnDev
#RedTeam
#CyberSec
#MeMBu

opensourcemalware.com/blog/introdu...
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
WeaselBiscuit is a lean new infostealer hiding in npm that we suspect was created by DPRK
opensourcemalware.com
September 20, 2026 at 10:02 PM
🚨Researchers found 13 npm packages delivering a previously undocumented JavaScript stealer dubbed WeaselBiscuit. It shares functionality with DPRK-linked BeaverTail and OtterCookie, but is smaller and stripped of many of their capabilities. #WeaselBiscuit #Cybersecurity
September 22, 2026 at 9:38 AM
The WeaselBiscuit Threat: Anatomy of a Lightweight JavaScript Stealer in npm

Analysis of the WeaselBiscuit JavaScript stealer spreading via 13 npm packages to harvest sensitive Chrome extension data and developer credentials.

#npm #Malware

Read more →
The WeaselBiscuit Threat: Anatomy of a Lightweight JavaScript Stealer in npm
Analysis of the WeaselBiscuit JavaScript stealer spreading via 13 npm packages to harvest sensitive Chrome extension data and developer credentials.
calmvibez.com
September 19, 2026 at 11:03 AM
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage thehackernews.com/2026/09/weas...
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Thirteen npm packages deliver WeaselBiscuit, a JavaScript stealer that harvests Chrome extension storage across Windows, macOS, and Linux.
thehackernews.com
September 19, 2026 at 1:42 PM
"WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials" published by OpenSourceMalware. #NPM, #WeaselBiscuit https://opensourcemalware.com/blog/introducing-weaselbiscuit
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
opensourcemalware.com
September 17, 2026 at 5:14 AM
Malicious npm packages caught spreading WeaselBiscuit stealer—a new JavaScript malware targeting Chrome extension storage. 13 packages compromised; code links to North Korean…

https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html

#cybersecurity #infosec
September 22, 2026 at 1:30 PM
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
opensourcemalware.com
September 19, 2026 at 6:54 PM
WeaselBiscuit triggers when an npm package is imported, pulling its payload from an Npoint dead drop and executing it in memory. It profiles hosts and harvests Chrome extension storage across Windows, macOS and Linux. On Windows, it can also steal clipboard data and keystrokes.
September 22, 2026 at 9:38 AM
New JS stealer WeaselBiscuit hits npm—targets Chrome extension storage, keystrokes. #WeaselBiscuit #npm #Malware #InfoStealer #Cybersecurity #ThreatIntel thedailytechfeed.com/weaselbiscui...
September 18, 2026 at 11:56 AM
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.

The new malware fami…
#hackernews #news
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and
thehackernews.com
September 19, 2026 at 2:01 PM
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 19, 2026 at 1:39 PM
Threat actors are distributing 13 malicious npm packages that deliver a new, lightweight JavaScript stealer named WeaselBiscuit. The malware shows […]
13 npm Packages Deliver WeaselBiscuit Stealer
Threat actors are distributing 13 malicious npm packages that deliver a new, lightweight JavaScript stealer named WeaselBiscuit. The malware shows […]
bitnewsbot.com
September 18, 2026 at 1:34 PM
Chrome Bleeds Wallets While Everyone Pretends This Is Fine
PANIC 67% | Lag 0.0h | WeaselBiscuit is stealing browser-stored data and wallet-related information from Chrome systems. Ru
#AfterShockIndex
READ MORE
September 20, 2026 at 11:15 AM
WeaselBiscuit Stealer Found in 13 Malicious npm Packages #BeaverTailmalware #ChromeExtensionSecurity #ContagiousInterview
WeaselBiscuit Stealer Found in 13 Malicious npm Packages
Researchers have discovered 13 npm packages carrying a previously undocumented JavaScript information stealer called WeaselBiscuit, introducing yet another malicious threat to the npm package ecosystem. In addition to linking the packages together via shared indicators, OpenSourceMalware found several similarities between BeaverTail and OtterCookie, two North Korean malware families.  A number of packages are included, including @biz44/id10-client, @biz44/id12-client, @biz44/id44-client, @biz44/id79-client, @biz44/id95-client, @biz44/id99-client, @biz44/process-runtime-utils, @biz44/runtime-utils, @biz44/engin1, id79-client, process-lhpm, process-mite, and process-tailwind. Many were first observed between September 12 and September 16, 2026, with some versions still available on NPM at the time of analysis.  In comparison to BeaverTail and OtterCookie, WeaselBiscuit appears much smaller. In addition to remote access and cryptocurrency theft functions, the malware focuses on profiling hosts and collecting data collected by Chrome extensions rather than carrying a broad range of remote access functions. Malware loaders are launched when a compromised package is imported, causing detached Node.js processes to begin execution. After retrieving an encoded payload from an Npoint URL, the loader executes the decoded code directly in memory. Following execution, the malware obtains its command-and-control configuration from another Npoint endpoint before connecting to 103.170.217.184:8787. Among the data collected are hostnames, usernames, operating systems, CPUs, and memory, as well as local and public IP addresses.  Chrome profiles are also searched for extension storage on Windows, Mac OS, and Linux platforms. Chrome's Local Extension Settings directory may contain information associated with browser extensions, including cryptocurrency wallet extensions, which makes this collection especially significant.  Instead of relying on a specific list of wallet extensions, OpenSourceMalware reported the stealer uploads readable, non-empty files from these locations. C2 servers can also provide commands for monitoring the clipboard and logging Windows keystrokes.  Despite these capabilities, the recovered malware does not include direct wallet draining functionality, browser password decryption, seed phrase searching, screenshots, or a remote shell access. Additionally, some BeaverTail and OtterCookie activities have a Python-based InvisibleFerret stage that is not present in any other activity.  Possible Links to DPRK Malware WeaselBiscuit has been compared to malware associated with the DPRK-linked Contagious Interview campaign, but the attribution has yet to be confirmed. OpenSourceMalware did not find conclusive evidence that the attack was originated by North Korea based on operational infrastructure, victimology, campaign metadata or other identifying materials.  WeaselBiscuit employs the dead-drop technique of Npoint.io as a dead-drop service, a technique previously observed in Contagious Interview campaigns. Some of its technical indicators, however, overlap with earlier campaigns. Additionally, its code performs public IP and geolocation checks using IPify.org and IP-API.com, while parts of its command-and-control design are similar to OtterCookie's.  Among the numeric identifiers found in the malware are 10, 12, 44, 79, 95, and 99. These identifiers are similar to campaign markers associated with PolinRider activity, however their exact purpose in WeaselBiscuit is unclear. In terms of capability, BeaverTail and OtterCookie are more closely related.  Several features are retained in WhistlerBiscuit, including system profiling, Chrome extension data collection, clipboard monitoring, and keylogging, all of which are common to those malware families. However, several of their heavier features are removed, including remote access functions, wallet draining capabilities, screenshots, and secondary payload delivery.  Researchers at Cisco Talos observed a similar overlap in October 2025, when they discovered that the node-nvm-ssh package contained characteristics related to both BeaverTail and OtterCookie. The findings suggest that code and techniques from these malware families have been found in a variety of combinations within npm-based malicious code.  The WeaselBiscuit stealer should be viewed for the time being as a distinctive lightweight stealer with distinct technical similarities to DPRK-related tooling rather than a new DPRK malware family confirmed by the DPRK. For a more conclusive attribution, further evidence from infrastructure, campaigns, or code levels would be required. With the discovery of WeaselBiscuit, security risks are highlighted within the npm ecosystem, particularly for developers utilizing third-party packages. In addition to the ability to collect Chrome extension data and similarity to BeaverTail and OtterCookie, it warrants continued investigation as researchers investigate its origins and wider activities.
dlvr.it
September 19, 2026 at 2:52 PM
🤖 New JS stealer "WeaselBiscuit" distributed via 13 npm packages, harvesting Chrome extension storage. Linked to DPRK Contagious Interview campaign (BeaverTail overlap).
https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
September 18, 2026 at 1:22 PM
Thirteen npm packages run WeaselBiscuit upon import to nick Chrome extension data. Why do we even bother checking dependencies anymore?

#npmNightmare #JustAnotherDay
September 19, 2026 at 6:33 AM
WeaselBiscuit Stealer Spreads Via 13 Npm Packages to Harvest Chrome Extension Storage https://packetstorm.news/news/view/43606 #news
September 18, 2026 at 9:04 PM
Chrome拡張機能ストレージから情報を窃取するマルウェア「WeaselBiscuit Stealer」が、13個のnpmパッケージを通じて拡散。DPRK関連マルウェアとの類似性も確認。
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Thirteen npm packages deliver WeaselBiscuit, a JavaScript stealer that harvests Chrome extension storage across Windows, macOS, and Linux.
thehackernews.com
September 18, 2026 at 11:02 AM
🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Leer Más / Read More...
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Haz clic para acceder al contenido completo.
thehackernews.com
September 18, 2026 at 12:11 PM
WeaselBiscuit盗聴マルウェア、npmパッケージ13個経由で配布中

JavaScriptスティーラー「WeaselBiscuit」がnpmパッケージ13個に混入。Windows・macOS・Linuxで動作し、Chrome拡張機能のストレージを盗聴します。npmの依存関係チェックが重要です。

#マルウェア #情報セキュリティ
WeaselBiscuit盗聴マルウェア、npmパッケージ13個経由で配布中
JavaScriptスティーラー「WeaselBiscuit」がnpmパッケージ13個に混入。Windows・macOS・Linuxで動作し、Chrome拡張機能のストレージを盗聴します。npmの依存関係チェックが重要です。
thehackernews.com
September 18, 2026 at 11:01 AM
Here we go again with supply chain joy, as thirteen npm packages execute WeaselBiscuit directly into memory upon import. Anyone across Windows, macOS, and Linux who dared to pull these delightful scripts found their Chrome extension storage scooped up for a DPRK campaign. Keeping...

Read full story
September 19, 2026 at 6:33 AM
Thirteen npm packages deliver WeaselBiscuit, a smaller JavaScript stealer borrowing functions from DPRK malware BeaverTail and OtterCookie but lacking remote access and other heavy capabilities.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 18, 2026 at 11:04 AM