AI Weekly Malaysia

Back to items Summaries

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

ID
25887
Status
summarized
Published
18 Sep 2026, 6:40 PM
Fetched
18 Sep 2026, 6:59 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.0
Created
18 Sep 2026, 7:00 PM
Tags
Audience
developersvibe_coders

What happened

Researchers discovered 13 npm packages delivering WeaselBiscuit, a lightweight JavaScript stealer that borrows from DPRK-linked BeaverTail and OtterCookie malware. Triggered on npm import, it pulls malware from an Npoint dead drop, executes in memory, and harvests Chrome extension storage across Windows, macOS, and Linux — but lacks persistence, remote access, or crypto wallet-draining capabilities.

Why it matters

Developers should immediately check their dependency trees for the 13 named packages (all under @biz44/* plus engin1, id79-client, process-lhpm, process-mite, process-tailwind) and audit whether any CI/CD or dev environments have imported them. The attack vector is simply running npm install — no social engineering beyond publishing a package — so lockfiles and dependency review processes are the practical defense.

Discussion angle

How many of us actually review new npm dependencies before installing them, and what tooling (npm audit, socket.dev, lockfile linting) is worth adopting given that this attack required zero user interaction beyond an import?

Top