WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Researchers discovered WeaselBiscuit, a stripped-down JavaScript stealer delivered via 13 malicious npm packages, harvesting Chrome extension storage with suspected DPRK links.
OpenSourceMalware identified 13 npm packages, including @biz44/id10-client and process-tailwind, delivering a previously undocumented stealer named WeaselBiscuit. Triggered on npm import, a loader.js pulls the payload from an Npoint dead drop, executes it in memory, and harvests Chrome extension storage (LevelDB) on Windows, macOS, and Linux, with clipboard and keylogging on Windows via C2 at 103.170.217.184:8787. It shares tradecraft with DPRK Contagious Interview's BeaverTail and OtterCookie, including Npoint.io usage and numerical campaign IDs, but definitive attribution is not established.