The record
Written from the 1 report below. Nothing here is unsourced.
- Researchers have discovered 13 malicious npm packages that distribute a new information-stealing malware called WeaselBiscuit.
- The malicious packages include names such as @biz44/id10-client, engin1, process-mite, and process-tailwind.
- WeaselBiscuit is a lightweight JavaScript stealer that shares functions with BeaverTail and OtterCookie, two malware strains linked to North Korea's Contagious Interview campaign.
- Once installed, the malware harvests Chrome extension storage on Windows, macOS, and Linux, and can also log clipboard contents and keystrokes on Windows machines.
- The extension-storage theft matters because it can expose cryptocurrency wallet-extension data and other sensitive information held by browser extensions.
What to watch next
- Whether investigators confirm attribution of WeaselBiscuit to North Korean threat actors.
- Whether npm removes the 13 malicious packages and other similar ones are discovered.
- Whether the operators behind the C2 server 103.170.217[.]184:8787 are identified or the server is taken down.
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Paul McCarty
security researcher
1 quote · 1 outlet
“It's smaller, lighter, and stripped down, with many of the heavier functions removed entirely,”
In the article
…family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and OtterCookie. " It's smaller, lighter, and stripped down, with many of the heavier functions removed entirely, " security researcher Paul McCarty (aka 6mile) said. The names of the packages are below - - @biz44/id10-client - @biz44/id12-client - @biz44/id44-client - @biz44/id79-client - @biz44/id95-client - @biz44/id99-client -…
Jenn Gile
co-founder of OpenSourceMalware
1 quote · 1 outlet
“It's a stripped down stealer that borrows several functions from DPRK's BeaverTail and OtterCookie, but is much smaller and self-contained,”
In the article
…- @biz44/id44-client - @biz44/id79-client - @biz44/id95-client - @biz44/id99-client - @biz44/process-runtime-utils - @biz44/runtime-utils - engin1 - id79-client - process-lhpm - process-mite - process-tailwind " It's a stripped down stealer that borrows several functions from DPRK's BeaverTail and OtterCookie, but is much smaller and self-contained, " Jenn Gile, co-founder of OpenSourceMalware, said in a statement shared with The Hacker News. "Hence the 'WeaselBiscuit' name, because a weasel is smaller than an otter, and we can argue that biscuits are less fancy…
Coverage1
All filed from India
Named North Korea · BeaverTail · npm · OtterCookie · Cisco Talos · Jenn Gile · Npoint · NTT Security Holdings · OpenSourceMalware · Paul McCarty · WeaselBiscuit
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
