Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WeaselBiscuit Malware Detected in 13 npm Packages

WeaselBiscuit Malware Detected in 13 npm Packages

Posted on September 18, 2026 By CWS

Researchers in cybersecurity have identified a group of 13 npm packages that are being used to distribute a new type of JavaScript malware, referred to as WeaselBiscuit. This newly discovered malware has been linked to North Korea’s previous cyber campaigns, specifically mirroring functionalities seen in BeaverTail and OtterCookie, two known malware strains.

Characteristics of WeaselBiscuit Malware

According to OpenSourceMalware, WeaselBiscuit’s design is notably streamlined, removing many of the complex features found in its predecessors. Security expert Paul McCarty highlights that the malware is lighter and more self-contained compared to BeaverTail and OtterCookie. Jenn Gile of OpenSourceMalware elaborates that the name reflects its smaller scale, akin to how a weasel is smaller than an otter.

The npm packages involved include names such as @biz44/id10-client and @biz44/process-runtime-utils. These packages facilitate the malware’s operation by importing a loader script that downloads the main malicious code from a remote server.

Functionality and Impact

WeaselBiscuit operates without the advanced features seen in other malware. It lacks remote access, persistence mechanisms, and cryptocurrency wallet theft capabilities. Instead, it focuses on accessing Chrome extension storage, potentially compromising sensitive data within those extensions.

The malware retrieves its command-and-control configuration from a separate URL and gathers information from the infected host. It is capable of logging clipboard activities and keystrokes, specifically on Windows systems. This functionality poses a significant risk by exposing sensitive data stored in browser extensions.

Potential Attribution to North Korea

While OpenSourceMalware acknowledges similarities with North Korean operations, there is no conclusive evidence linking WeaselBiscuit directly to North Korean threat actors. However, the use of Npoint.io and similar command structures suggest a potential connection.

These findings align with previous observations by NVISO and Cisco Talos, which noted the blending of features from BeaverTail and OtterCookie in other npm packages. The continued evolution of these threats underscores the importance of vigilance in the cybersecurity community.

As the investigation into WeaselBiscuit continues, researchers stress the necessity of protecting systems from such malware, particularly those that could exploit vulnerabilities in widely used platforms like npm.

The Hacker News Tags:BeaverTail, C2 Server, Chrome extension, Contagious Interview, Cybersecurity, DPRK, InvisibleFerret, Jenn Gile, LevelDB, Malware, npm packages, OpenSourceMalware, OtterCookie, Paul McCarty, WeaselBiscuit

Post navigation

Previous Post: Phishing Scam Targets T-Mobile Users with Fake Rewards
Next Post: Gyazo Data Breach Exposes 23 Million User Records

Related Posts

Weekly Cybersecurity Highlights: Rogue AI and Exploits Weekly Cybersecurity Highlights: Rogue AI and Exploits The Hacker News
Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware The Hacker News
Enhancing IAM Security with Identity Visibility Platforms Enhancing IAM Security with Identity Visibility Platforms The Hacker News
Flaw in AI APIs Allows Extraction of Hidden Data Flaw in AI APIs Allows Extraction of Hidden Data The Hacker News
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors The Hacker News
Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages
  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages
  • Phishing Scam Targets T-Mobile Users with Fake Rewards
  • Global Crackdown Halts NightmareStresser DDoS Service

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark