What happened
Researchers uncovered a set of 13 npm packages that act as a delivery chain for a stripped-down JavaScript stealer dubbed WeaselBiscuit.
How the loader works
The packages contain a loader.js script. When executed it contacts a dead-drop page on Npoint.io, pulls the main payload into memory and runs it without touching disk.
Immediately after loading, the malware reaches out to a second Npoint URL to fetch its C2 configuration, then profiles the host operating system.
Data it steals
Its primary target is the LevelDB store used by Chrome extensions (the “Local Extension Settings” directory). Every readable, non-empty file there is read and uploaded.
On Windows machines the stealer can, on command from the C2 server at 103.170.217.184:8787, capture clipboard contents and record keystrokes.
It also gathers basic system information and can enumerate other installed npm packages.
Tradecraft signals
The campaign consistently uses Npoint.io, api.ipify.org and ip-api.com for host discovery and configuration delivery. Each install is tagged with a numeric ID (10, 12, 44, 79, 95, 99) that appears in the package name.
Package list
- @biz44/id10-client
- @biz44/id12-client
- @biz44/id44-client
- @biz44/id79-client
- @biz44/id95-client
- @biz44/id99-client
- @biz44/process-runtime-utils
- @biz44/runtime-utils
- engin1
- id79-client
- process-lhpm
- process-mite
- process-tailwind
Who might be behind it?
Researchers noted functional overlap with DPRK-associated malware families such as BeaverTail and OtterCookie, but attribution to North Korean actors remains unconfirmed.
Defensive steps
Enterprises should treat any unexpected npm dependency as suspicious.
- Run
npm auditand enforce strict version pinning in lockfiles. - Block outbound connections to Npoint.io,
api.ipify.org,ip‑api.comand the IP103.170.217.184unless explicitly required. - Monitor processes that read the Chrome “Local Extension Settings” directory or spawn
loader.jswithout a legitimate build step. - Enable filesystem integrity monitoring on the Chrome profile folders.
- Educate developers to review scripts in newly added packages before publishing.
