WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...
AI Analysis
Technical Summary
WeaselBiscuit is a newly identified JavaScript infostealer malware distributed through 11 malicious npm packages. It operates by importing malicious code via npm, launching a detached Node.js process to execute payloads retrieved from various Npoint URLs. The malware communicates with a C2 server hosted at IP 103.170.217.184 on port 8787. It performs host profiling, steals Chrome extension storage containing wallet signing states, captures clipboard data, and logs keystrokes on Windows systems when instructed. This malware is a stripped-down variant of DPRK-linked BeaverTail and OtterCookie families, lacking advanced capabilities such as wallet draining, password decryption, Python-based second stages, screenshot capture, and remote shell access. Numeric campaign identifiers embedded in package names facilitate tracking of infection campaigns. Technical overlaps, including use of Npoint dead-drop patterns and IP geolocation techniques, suggest possible DPRK attribution, though definitive confirmation is pending further investigation.
Potential Impact
The malware compromises infected systems by stealing sensitive information including Chrome extension data related to wallet signing, clipboard contents, and keystrokes on Windows. This can lead to exposure of cryptocurrency wallet states and potentially other sensitive user data. However, it does not currently perform wallet draining, password decryption, or remote control functions, limiting its direct destructive impact compared to related malware families.
Mitigation Recommendations
No official patch or remediation is indicated as this is malware distributed via malicious npm packages. Mitigation should focus on preventing installation of untrusted npm packages, monitoring for suspicious Node.js processes, and blocking communication to the identified C2 IP (103.170.217.184) and associated Npoint URLs. Organizations should audit npm dependencies and employ supply chain security best practices to reduce risk.
Indicators of Compromise
- url: http://103.170.217.184:8787
- ip: 103.170.217.184
- hash: 7b15605f23b131b3eeea57e031ae7cb32fc4b78c7bbb2025aa7a561ea5ae5159
- url: https://api.npoint.io/24c12c4b66a29747764f
- url: https://api.npoint.io/24c25d5f5fcbb0992a4f
- url: https://api.npoint.io/33e8d008c334b060adad
- url: https://api.npoint.io/37c0a0c68bf7a94ed731
- url: https://api.npoint.io/641d37178a880b1e8b8f
- url: https://api.npoint.io/933a731a5e97f4b45249
- url: https://api.npoint.io/ddae72efbb6714fae922
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
Description
A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
WeaselBiscuit is a newly identified JavaScript infostealer malware distributed through 11 malicious npm packages. It operates by importing malicious code via npm, launching a detached Node.js process to execute payloads retrieved from various Npoint URLs. The malware communicates with a C2 server hosted at IP 103.170.217.184 on port 8787. It performs host profiling, steals Chrome extension storage containing wallet signing states, captures clipboard data, and logs keystrokes on Windows systems when instructed. This malware is a stripped-down variant of DPRK-linked BeaverTail and OtterCookie families, lacking advanced capabilities such as wallet draining, password decryption, Python-based second stages, screenshot capture, and remote shell access. Numeric campaign identifiers embedded in package names facilitate tracking of infection campaigns. Technical overlaps, including use of Npoint dead-drop patterns and IP geolocation techniques, suggest possible DPRK attribution, though definitive confirmation is pending further investigation.
Potential Impact
The malware compromises infected systems by stealing sensitive information including Chrome extension data related to wallet signing, clipboard contents, and keystrokes on Windows. This can lead to exposure of cryptocurrency wallet states and potentially other sensitive user data. However, it does not currently perform wallet draining, password decryption, or remote control functions, limiting its direct destructive impact compared to related malware families.
Defensive Guidance
No official patch or remediation is indicated as this is malware distributed via malicious npm packages. Mitigation should focus on preventing installation of untrusted npm packages, monitoring for suspicious Node.js processes, and blocking communication to the identified C2 IP (103.170.217.184) and associated Npoint URLs. Organizations should audit npm dependencies and employ supply chain security best practices to reduce risk.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://opensourcemalware.com/blog/introducing-weaselbiscuit"]
- Adversary
- DPRK
- Pulse Id
- 6aad3e7f8cc155ff864b444b
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://103.170.217.184:8787 | — | |
urlhttps://api.npoint.io/24c12c4b66a29747764f | — | |
urlhttps://api.npoint.io/24c25d5f5fcbb0992a4f | — | |
urlhttps://api.npoint.io/33e8d008c334b060adad | — | |
urlhttps://api.npoint.io/37c0a0c68bf7a94ed731 | — | |
urlhttps://api.npoint.io/641d37178a880b1e8b8f | — | |
urlhttps://api.npoint.io/933a731a5e97f4b45249 | — | |
urlhttps://api.npoint.io/ddae72efbb6714fae922 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip103.170.217.184 | CC=IN ASN=AS133292 ads royalnet communication pvt ltd |
Hash
| Value | Description | Copy |
|---|---|---|
hash7b15605f23b131b3eeea57e031ae7cb32fc4b78c7bbb2025aa7a561ea5ae5159 | — |
Threat ID: 6aad4b5855bf5e2cf51f58e2
Added to database: 09/18/2026, 14:31:52 UTC
Last enriched: 09/18/2026, 14:47:30 UTC
Last updated: 09/19/2026, 02:30:07 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.