Skip to main content

WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials

0
Medium
Published: 09/18/2026 (09/18/2026, 13:37:03 UTC)
Source: AlienVault OTX General

Description

A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 14:47:30 UTC

Technical Analysis

WeaselBiscuit is a newly identified JavaScript infostealer malware distributed through 11 malicious npm packages. It operates by importing malicious code via npm, launching a detached Node.js process to execute payloads retrieved from various Npoint URLs. The malware communicates with a C2 server hosted at IP 103.170.217.184 on port 8787. It performs host profiling, steals Chrome extension storage containing wallet signing states, captures clipboard data, and logs keystrokes on Windows systems when instructed. This malware is a stripped-down variant of DPRK-linked BeaverTail and OtterCookie families, lacking advanced capabilities such as wallet draining, password decryption, Python-based second stages, screenshot capture, and remote shell access. Numeric campaign identifiers embedded in package names facilitate tracking of infection campaigns. Technical overlaps, including use of Npoint dead-drop patterns and IP geolocation techniques, suggest possible DPRK attribution, though definitive confirmation is pending further investigation.

Potential Impact

The malware compromises infected systems by stealing sensitive information including Chrome extension data related to wallet signing, clipboard contents, and keystrokes on Windows. This can lead to exposure of cryptocurrency wallet states and potentially other sensitive user data. However, it does not currently perform wallet draining, password decryption, or remote control functions, limiting its direct destructive impact compared to related malware families.

Defensive Guidance

No official patch or remediation is indicated as this is malware distributed via malicious npm packages. Mitigation should focus on preventing installation of untrusted npm packages, monitoring for suspicious Node.js processes, and blocking communication to the identified C2 IP (103.170.217.184) and associated Npoint URLs. Organizations should audit npm dependencies and employ supply chain security best practices to reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://opensourcemalware.com/blog/introducing-weaselbiscuit"]
Adversary
DPRK
Pulse Id
6aad3e7f8cc155ff864b444b

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttp://103.170.217.184:8787
urlhttps://api.npoint.io/24c12c4b66a29747764f
urlhttps://api.npoint.io/24c25d5f5fcbb0992a4f
urlhttps://api.npoint.io/33e8d008c334b060adad
urlhttps://api.npoint.io/37c0a0c68bf7a94ed731
urlhttps://api.npoint.io/641d37178a880b1e8b8f
urlhttps://api.npoint.io/933a731a5e97f4b45249
urlhttps://api.npoint.io/ddae72efbb6714fae922

Ip

ValueDescriptionCopy
ip103.170.217.184
CC=IN ASN=AS133292 ads royalnet communication pvt ltd

Hash

ValueDescriptionCopy
hash7b15605f23b131b3eeea57e031ae7cb32fc4b78c7bbb2025aa7a561ea5ae5159

Threat ID: 6aad4b5855bf5e2cf51f58e2

Added to database: 09/18/2026, 14:31:52 UTC

Last enriched: 09/18/2026, 14:47:30 UTC

Last updated: 09/19/2026, 02:30:07 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses