WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
ID: deec556b-a02e-5c9a-b0b9-a959fc05798f
STIX ID: report--deec556b-a02e-5c9a-b0b9-a959fc05798f
Feed Name: OpenSourceMalware Blog
Date Published: 2026-09-17
Date Updated: 2026-09-17
Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2
OpenSourceMalware researchers describe "WeaselBiscuit," a lightweight Node.js infostealer hidden in multiple malicious npm packages that fetch a Base64 second-stage from api.npoint.io, executes it in memory, and exfiltrates Chrome extension LevelDB data, clipboard contents, and Windows keystrokes to an Express C2 at 103.170.217.184:8787; the report provides package names, Npoint resolver URLs, a second-stage SHA-256, recommended investigative actions, and tentatively links the tooling to DPRK-associated BeaverTail/OtterCookie tradecraft while noting reduced capabilities and limited persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
