negativeSYS.SOURCE: The Hacker News• 2026-09-18T16:10:06+05:30
WeaselBiscuit Malware Exploits 13 npm Packages to Steal Chrome Extension Data
A new JavaScript stealer named WeaselBiscuit is distributed through 13 npm packages, targeting Chrome extension storage data across multiple operating systems. The malware exhibits similarities to DPRK-linked campaigns but lacks definitive attribution, focusing on harvesting sensitive extension data rather than cryptocurrency wallets.
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.
The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and
*** END OF TRANSMISSION ***