Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

WeaselBiscuit npm Stealer Hijacks 13 Packages to Exfiltrate Chrome Data

DECRYPTED BY: Leo Carmichael | TIMESTAMP: 2026-09-18 T 20:16:41 Z | [ 1 MIN READ ]
WeaselBiscuit npm Stealer Hijacks 13 Packages to Exfiltrate Chrome Data
1 Min Read
Share

WeaselBiscuit npm Threat Spreads via ↓ 13 Packages

WeaselBiscuit npm is a newly catalogued JavaScript stealer that infiltrates developers through a chain of thirteen npm modules, siphoning Chrome extension storage for unknown actors.

Security analysts at OpenSourceMalware traced the code to a modular framework that mirrors components of the DPRK‑linked BeaverTail and Contagious Interview campaigns, suggesting state‑sponsored origins.

“We observed the payload pulling Chrome extension storage within seconds,” said a researcher.

The malicious packages masquerade as utility libraries, each pulling a tiny dependency that collectively assembles the full exfiltration engine. Once installed, the code executes silently in the browser context, harvesting Reuters-cited data such as saved passwords and tokens.

Defenders are urged to audit their supply chains and enforce strict version pinning, especially after the pandemic highlighted the fragility of remote development pipelines.


Intel provided by Leo Carmichael (Special Assignments Reporter).
(Note: Leo Carmichael is covering this desk while Kaelen Frost is on annual vacation.)

Global Data Feed

More from this Intel

Linux kernel exploit exposes four local‑root flaws, patches urged

Linux kernel exploit exposes four local‑root flaws, patches urged

Sep 18, 2026
Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Sep 18, 2026
RatHat Android malware exploits AI to automate device control – what you need to know

RatHat Android malware exploits AI to automate device control –...

Sep 18, 2026
AI security spending soars as fear eclipses proven value

AI security spending soars as fear eclipses proven value

Sep 17, 2026
Issabel Framework Flaw Triggers Remote Code Execution – Critical CVE‑2026‑89026 Exploited

Issabel Framework Flaw Triggers Remote Code Execution – Critical CVE‑2026‑89026...

Sep 17, 2026
Iranian Hackers Deploy CHOSEN BRICK Malware to Spy on Dissidents Worldwide

Iranian Hackers Deploy CHOSEN BRICK Malware to Spy on Dissidents...

Sep 16, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.