WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials

2026-09-17 Open Source Malware

https://opensourcemalware.com/blog/introducing-weaselbiscuit

Thumbnail for WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials

OpenSourceMalware found 11 malicious npm packages delivering WeaselBiscuit, a compact Node.js infostealer that executes an Npoint-hosted payload in memory and communicates with an HTTP C2 at 103.170.217.184:8787. It profiles infected systems, steals Chrome extension storage, and can collect clipboard contents and Windows keystrokes when enabled by the operator. The researchers tentatively link it to DPRK-associated Contagious Interview tradecraft because of its npm delivery, Npoint dead drops, data targets, and operational patterns, while noting major differences from BeaverTail and OtterCookie. The attribution remains low to moderate confidence because exclusive infrastructure, victimology, and conclusive shared-code evidence are absent.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://api.npoint.io/24c12c4b6… 2026-09-17 2026-09-17
URL https://api.npoint.io/933a731a5… 2026-09-17 2026-09-17
URL https://api.npoint.io/ddae72efb… 2026-09-17 2026-09-17
URL https://api.npoint.io/33e8d008c… 2026-09-17 2026-09-17
URL https://api.npoint.io/641d37178… 2026-09-17 2026-09-17
URL https://api.npoint.io/37c0a0c68… 2026-09-17 2026-09-17
URL https://api.npoint.io/24c25d5f5… 2026-09-17 2026-09-17
URL http://103.170.217.184:8787 2026-09-17 2026-09-17
HASH 7b15605f23b131b3eeea57e031ae7cb… 2026-09-17 2026-09-17
IPv4 103.170.217.184 2026-09-17 2026-09-17

Related Reports

« Back