opensourcemalware.com New WeaselBiscuit JavaScript Stealer Discovered in npm Packages
Article Content
- •WeaselBiscuit spreads via 13 malicious npm packages.
- •The malware has similarities with DPRK's BeaverTail and OtterCookie but is simpler.
- •It can harvest Chrome extension storage and log clipboard contents on Windows.
Cybersecurity researchers identified a new JavaScript stealer named WeaselBiscuit, which spreads through 13 malicious npm packages. This malware is believed to have functional overlaps with DPRK-associated strains BeaverTail and OtterCookie but is smaller and lacks certain advanced features. It operates by executing a loader script upon npm import, fetching its payload from an Npoint URL and running it in memory. The malware profiles the host system and can harvest Chrome extension storage across multiple operating systems. While it can log clipboard contents and keystrokes on Windows, it does not possess the same capabilities for draining cryptocurrency wallets as its predecessors. OpenSourceMalware has tentatively attributed this malware to DPRK, but definitive evidence linking it to North Korean operators is still lacking. The discovery highlights a new threat vector targeting developers and cryptocurrency users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track FAMOUS CHOLLIMA, BeaverTail and Vercel in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
North Korean Fake Worker Scam Targets US Companies North Korean operatives are infiltrating US companies by posing as foreign IT specialists, exploiting trust and business processes to gain legitimate access. These fake workers often secure remote employment under false identities, with reports indicating that they have cost organizations hundreds of millions since…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…