Researchers at OpenSourceMalware identified a cluster of 13 npm packages delivering a previously undocumented JavaScript stealer named WeaselBiscuit, including seven scoped @biz44/* packages (id10-client, id12-client, id44-client, id79-client, id95-client, id99-client, process-runtime-utils, runtime-utils) and the unscoped engin1, id79-client, process-lhpm, process-mite and process-tailwind. The malware shows functional overlap with BeaverTail and OtterCookie, the strains associated with North Korea's Contagious Interview campaign, but is markedly smaller: it has no remote access, no persistence, no cryptocurrency wallet-draining code and no secondary-payload delivery, and is triggered by importing the package, which causes loader.js to pull the main payload from an Npoint dead drop and execute it in memory. Harvesting targets Chrome extension storage. The re-use of DPRK tradecraft in a lighter, self-contained imitator is the notable part — the toolchain is being copied by actors who are not the original operators.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-19 |
| Source | The Hacker News |
| Reliability | Tier 2 |