VMTech
Discuss a project

WeaselBiscuit found in 13 npm packages targeting Chrome extension data

WeaselBiscuit found in 13 npm packages targeting Chrome extension data

Researchers at OpenSourceMalware have identified 13 npm packages that deliver a previously undocumented JavaScript information stealer dubbed WeaselBiscuit. The packages include @biz44/id10-client, @biz44/id12-client, @biz44/id44-client, @biz44/id79-client, @biz44/id95-client, @biz44/id99-client, @biz44/process-runtime-utils, @biz44/runtime-utils, engin1, id79-client, process-lhpm, process-mite and process-tailwind.

The malware runs when a victim imports one of the packages. Its loader, loader.js, retrieves the principal payload from an Npoint dead drop and executes it directly in memory. It then obtains command-and-control configuration from a separate Npoint URL, profiles the host and collects Chrome extension storage on Windows, macOS and Linux.

A lightweight stealer with cross-platform reach

OpenSourceMalware describes WeaselBiscuit as smaller, lighter and more self-contained than two malware strains linked to the Democratic People's Republic of Korea's Contagious Interview campaign: BeaverTail and OtterCookie. It lacks remote access, persistence, cryptocurrency wallet-draining code and a mechanism to deploy secondary payloads such as InvisibleFerret.

Its reduced feature set does not eliminate the risk. The stealer uploads every readable, nonempty file beneath Chrome's Local Extension Settings directory. Those files form a raw LevelDB key/value store and may contain wallet-extension state or other sensitive data retained by installed extensions.

On Windows, commands from the command-and-control server at 103.170.217[.]184:8787 can additionally instruct the malware to capture clipboard contents and keystrokes. The cross-platform extension-storage collection means an affected development workstation may expose data held outside the browser's ordinary profile data.

Attribution signals remain inconclusive

Researchers observed functional overlap with BeaverTail and OtterCookie, both associated with Contagious Interview. BeaverTail has targeted software developers, IT professionals and cryptocurrency users since at least late 2022, while OtterCookie combines information theft with remote-access capabilities.

OpenSourceMalware stressed that the available evidence does not conclusively attribute WeaselBiscuit to North Korea. It cited no definitive operator infrastructure, victimology, campaign metadata or signing material. Still, the use of Npoint.io, nested public-IP and geolocation lookups through api.ipify.org and ip-api.com, overlapping command-and-control architecture, and numerical campaign identifiers 10, 12, 44, 79, 95 and 99 are tradecraft signals noted by the researchers.

What development teams should take from the discovery

The incident reinforces that an npm import can be an execution path, not merely a dependency declaration. Teams should identify whether any of the named packages entered build or development environments, review dependency provenance and imports, and assess whether Chrome extension-held data could be exposed on affected endpoints.

For businesses, the practical implication is to treat package governance and dependency review as safeguards for developer systems and the sensitive extension data stored on them.

#cybersecurity#npmsecurity#supplychain#malware
Open analytics
On the site 1 views
min read 4 18.09.2026
Instagram

WeaselBiscuit found in 13 npm packages targeting Chrome extension data

Open the post on Instagram ↗