logo

WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials

ID: deec556b-a02e-5c9a-b0b9-a959fc05798f

STIX ID: report--deec556b-a02e-5c9a-b0b9-a959fc05798f

Feed Name: OpenSourceMalware Blog

Threat Score
70/100

Date Published: 2026-09-17

Date Updated: 2026-09-17

Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2

...
...

OpenSourceMalware researchers describe "WeaselBiscuit," a lightweight Node.js infostealer hidden in multiple malicious npm packages that fetch a Base64 second-stage from api.npoint.io, executes it in memory, and exfiltrates Chrome extension LevelDB data, clipboard contents, and Windows keystrokes to an Express C2 at 103.170.217.184:8787; the report provides package names, Npoint resolver URLs, a second-stage SHA-256, recommended investigative actions, and tentatively links the tooling to DPRK-associated BeaverTail/OtterCookie tradecraft while noting reduced capabilities and limited persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.