WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
News Source : Internet
News Summary
- WeaselBiscuit malware family exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign.
- "It's a stripped down stealer that borrows several functions from DPRK's BeaverTail and OtterCookie, but is much smaller and self-contained," Jenn Gile, co-founder of OpenSourceMalware, said.
- There is no definitive evidence in terms of operator infrastructure, victimology, campaign metadata, or signing material to conclusively attribute it to North Korea.
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.
Never miss a story from us, subscribe to our newsletter