Skip to content
New WeaselBiscuit JavaScript Stealer Discovered in npm Packages

New WeaselBiscuit JavaScript Stealer Discovered in npm Packages

First seen 18 Sep 2026, 16:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 18:54 UTC

Cybersecurity researchers identified a new JavaScript stealer named WeaselBiscuit, which spreads through 13 malicious npm packages. This malware is believed to have functional overlaps with DPRK-associated strains BeaverTail and OtterCookie but is smaller and lacks certain advanced features. It operates by executing a loader script upon npm import, fetching its payload from an Npoint URL and running it in memory. The malware profiles the host system and can harvest Chrome extension storage across multiple operating systems. While it can log clipboard contents and keystrokes on Windows, it does not possess the same capabilities for draining cryptocurrency wallets as its predecessors. OpenSourceMalware has tentatively attributed this malware to DPRK, but definitive evidence linking it to North Korean operators is still lacking. The discovery highlights a new threat vector targeting developers and cryptocurrency users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
WeaselBiscuit identified
OpenSourceMalware discovered WeaselBiscuit in 13 npm packages, marking a new JavaScript stealer threat.
OpenSourceMalware
2026-09-18
Details published by The Hacker News
The Hacker News reported on WeaselBiscuit, detailing its capabilities and potential DPRK links.
The Hacker News

More articles in this cluster (3)

Following this threat?

Track FAMOUS CHOLLIMA, BeaverTail and Vercel in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed