WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
- ID
- 25887
- Status
- summarized
- Published
- 18 Sep 2026, 6:40 PM
- Fetched
- 18 Sep 2026, 6:59 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 18 Sep 2026, 7:00 PM
- Tags
- Audience
- developersvibe_coders
What happened
Researchers discovered 13 npm packages delivering WeaselBiscuit, a lightweight JavaScript stealer that borrows from DPRK-linked BeaverTail and OtterCookie malware. Triggered on npm import, it pulls malware from an Npoint dead drop, executes in memory, and harvests Chrome extension storage across Windows, macOS, and Linux — but lacks persistence, remote access, or crypto wallet-draining capabilities.
Why it matters
Developers should immediately check their dependency trees for the 13 named packages (all under @biz44/* plus engin1, id79-client, process-lhpm, process-mite, process-tailwind) and audit whether any CI/CD or dev environments have imported them. The attack vector is simply running npm install — no social engineering beyond publishing a package — so lockfiles and dependency review processes are the practical defense.
Discussion angle
How many of us actually review new npm dependencies before installing them, and what tooling (npm audit, socket.dev, lockfile linting) is worth adopting given that this attack required zero user interaction beyond an import?