Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WeaselBiscuit Malware Detected in 13 npm Packages

WeaselBiscuit Malware Detected in 13 npm Packages

Posted on September 18, 2026 By CWS

Researchers in cybersecurity have identified a group of 13 npm packages that are being used to distribute a new type of JavaScript malware, referred to as WeaselBiscuit. This newly discovered malware has been linked to North Korea’s previous cyber campaigns, specifically mirroring functionalities seen in BeaverTail and OtterCookie, two known malware strains.

Characteristics of WeaselBiscuit Malware

According to OpenSourceMalware, WeaselBiscuit’s design is notably streamlined, removing many of the complex features found in its predecessors. Security expert Paul McCarty highlights that the malware is lighter and more self-contained compared to BeaverTail and OtterCookie. Jenn Gile of OpenSourceMalware elaborates that the name reflects its smaller scale, akin to how a weasel is smaller than an otter.

The npm packages involved include names such as @biz44/id10-client and @biz44/process-runtime-utils. These packages facilitate the malware’s operation by importing a loader script that downloads the main malicious code from a remote server.

Functionality and Impact

WeaselBiscuit operates without the advanced features seen in other malware. It lacks remote access, persistence mechanisms, and cryptocurrency wallet theft capabilities. Instead, it focuses on accessing Chrome extension storage, potentially compromising sensitive data within those extensions.

The malware retrieves its command-and-control configuration from a separate URL and gathers information from the infected host. It is capable of logging clipboard activities and keystrokes, specifically on Windows systems. This functionality poses a significant risk by exposing sensitive data stored in browser extensions.

Potential Attribution to North Korea

While OpenSourceMalware acknowledges similarities with North Korean operations, there is no conclusive evidence linking WeaselBiscuit directly to North Korean threat actors. However, the use of Npoint.io and similar command structures suggest a potential connection.

These findings align with previous observations by NVISO and Cisco Talos, which noted the blending of features from BeaverTail and OtterCookie in other npm packages. The continued evolution of these threats underscores the importance of vigilance in the cybersecurity community.

As the investigation into WeaselBiscuit continues, researchers stress the necessity of protecting systems from such malware, particularly those that could exploit vulnerabilities in widely used platforms like npm.

The Hacker News Tags:BeaverTail, C2 Server, Chrome extension, Contagious Interview, Cybersecurity, DPRK, InvisibleFerret, Jenn Gile, LevelDB, Malware, npm packages, OpenSourceMalware, OtterCookie, Paul McCarty, WeaselBiscuit

Post navigation

Previous Post: Phishing Scam Targets T-Mobile Users with Fake Rewards
Next Post: Gyazo Data Breach Exposes 23 Million User Records

Related Posts

Mustang Panda Exploits Cloud Service in Indian Cyber Attacks Mustang Panda Exploits Cloud Service in Indian Cyber Attacks The Hacker News
New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs The Hacker News
Critical SAP Flaws Pose Severe Security Risks Critical SAP Flaws Pose Severe Security Risks The Hacker News
AI Slashes Workloads for vCISOs by 68% as SMBs Demand More – New Report Reveals AI Slashes Workloads for vCISOs by 68% as SMBs Demand More – New Report Reveals The Hacker News
WP Maps Pro Vulnerability Exploited to Create Admin Accounts WP Maps Pro Vulnerability Exploited to Create Admin Accounts The Hacker News
Lazarus Exploits Windows Flaw to Deploy New Backdoor Lazarus Exploits Windows Flaw to Deploy New Backdoor The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark