Malware

13 Malicious npm Packages Deliver WeaselBiscuit Stealer

⏱️ 3 min read📅 9/18/2026👁️ 17 views

What happened

Researchers uncovered a set of 13 npm packages that act as a delivery chain for a stripped-down JavaScript stealer dubbed WeaselBiscuit.

How the loader works

The packages contain a loader.js script. When executed it contacts a dead-drop page on Npoint.io, pulls the main payload into memory and runs it without touching disk.

Immediately after loading, the malware reaches out to a second Npoint URL to fetch its C2 configuration, then profiles the host operating system.

Data it steals

Its primary target is the LevelDB store used by Chrome extensions (the “Local Extension Settings” directory). Every readable, non-empty file there is read and uploaded.

On Windows machines the stealer can, on command from the C2 server at 103.170.217.184:8787, capture clipboard contents and record keystrokes.

It also gathers basic system information and can enumerate other installed npm packages.

Tradecraft signals

The campaign consistently uses Npoint.io, api.ipify.org and ip-api.com for host discovery and configuration delivery. Each install is tagged with a numeric ID (10, 12, 44, 79, 95, 99) that appears in the package name.

Package list

  • @biz44/id10-client
  • @biz44/id12-client
  • @biz44/id44-client
  • @biz44/id79-client
  • @biz44/id95-client
  • @biz44/id99-client
  • @biz44/process-runtime-utils
  • @biz44/runtime-utils
  • engin1
  • id79-client
  • process-lhpm
  • process-mite
  • process-tailwind

Who might be behind it?

Researchers noted functional overlap with DPRK-associated malware families such as BeaverTail and OtterCookie, but attribution to North Korean actors remains unconfirmed.

Defensive steps

Enterprises should treat any unexpected npm dependency as suspicious.

  • Run npm audit and enforce strict version pinning in lockfiles.
  • Block outbound connections to Npoint.io, api.ipify.org, ip‑api.com and the IP 103.170.217.184 unless explicitly required.
  • Monitor processes that read the Chrome “Local Extension Settings” directory or spawn loader.js without a legitimate build step.
  • Enable filesystem integrity monitoring on the Chrome profile folders.
  • Educate developers to review scripts in newly added packages before publishing.
#npm#WeaselBiscuit#Chrome extensions#stealer#JavaScript