A lighter stealer called WeaselBiscuit turns up in 13 npm packages

A small JavaScript stealer with fingerprints of North Korean developer-targeting campaigns has been found riding a cluster of malicious packages.

CSBadmin
2 Min Read

Developers who installed one of 13 npm packages may have handed over their browser extension data. The OpenSourceMalware team found the cluster and named the JavaScript stealer it carries WeaselBiscuit.

The modules mix scoped and unscoped names: a run of @biz44 packages, plus standalone entries such as process-runtime-utils, process-lhpm and process-tailwind. Paul McCarty, the researcher who goes by 6mile, called the payload smaller and lighter than its relatives, stripped of heavier functions entirely.

Those relatives are the point. WeaselBiscuit borrows from BeaverTail and OtterCookie, two strains used in the Contagious Interview campaign that North Korean operators aim at software developers. The team’s framing of the name is blunt: a weasel is smaller than an otter, and biscuits are less fancy than cookies.

Collection is crude and wide. Rather than sorting through fields, the stealer copies whole Local Extension Settings directories for its Chrome targets, lifting the raw LevelDB key and value store in one pass.

Several tradecraft choices point the same direction. Command infrastructure resembles OtterCookie’s. The operators stash data in the Npoint.io JSON service, resolve public IP and geolocation through api.ipify.org and ip-api.com, and stamp every install with a numeric campaign ID.

None of that is proof. OpenSourceMalware said it found no conclusive evidence in operator infrastructure, victimology, campaign metadata or signing material to attribute the work to Pyongyang. The response does not wait on attribution: audit dependencies, drop unknown scoped packages, and treat postinstall scripts from unfamiliar modules as hostile.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.