WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
2026-09-17 • Open Source Malware •
https://opensourcemalware.com/blog/introducing-weaselbiscuit
OpenSourceMalware found 11 malicious npm packages delivering WeaselBiscuit, a compact Node.js infostealer that executes an Npoint-hosted payload in memory and communicates with an HTTP C2 at 103.170.217.184:8787. It profiles infected systems, steals Chrome extension storage, and can collect clipboard contents and Windows keystrokes when enabled by the operator. The researchers tentatively link it to DPRK-associated Contagious Interview tradecraft because of its npm delivery, Npoint dead drops, data targets, and operational patterns, while noting major differences from BeaverTail and OtterCookie. The attribution remains low to moderate confidence because exclusive infrastructure, victimology, and conclusive shared-code evidence are absent.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://api.npoint.io/24c12c4b6… | 2026-09-17 | 2026-09-17 |
| URL | https://api.npoint.io/933a731a5… | 2026-09-17 | 2026-09-17 |
| URL | https://api.npoint.io/ddae72efb… | 2026-09-17 | 2026-09-17 |
| URL | https://api.npoint.io/33e8d008c… | 2026-09-17 | 2026-09-17 |
| URL | https://api.npoint.io/641d37178… | 2026-09-17 | 2026-09-17 |
| URL | https://api.npoint.io/37c0a0c68… | 2026-09-17 | 2026-09-17 |
| URL | https://api.npoint.io/24c25d5f5… | 2026-09-17 | 2026-09-17 |
| URL | http://103.170.217.184:8787 | 2026-09-17 | 2026-09-17 |
| HASH | 7b15605f23b131b3eeea57e031ae7cb… | 2026-09-17 | 2026-09-17 |
| IPv4 | 103.170.217.184 | 2026-09-17 | 2026-09-17 |