WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Researchers have identified a cluster of 13 npm packages that deliver a previously undocumented JavaScript stealer given the codename WeaselBiscuit, The Hacker News reported on September 18, 2026. The finding is attributed to OpenSourceMalware, which described WeaselBiscuit as a new malware family. According to the report, the stealer exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's Contagious Interview campaign. One of those strains is named in the excerpt as BeaverTail; the second strain is referenced but its name is cut off in the provided text. The npm packages were found to spread WeaselBiscuit, and the stealer harvests Chrome extension storage, per the source. The excerpt does not specify which packages are involved, how many downloads they received, when they were published, or whether they remain available. It also does not describe the campaign's targeting, the data exfiltration path, or any response from npm or the researchers beyond the initial discovery. The report frames WeaselBiscuit as previously undocumented and links its functionality to the Contagious Interview-associated strains rather than stating direct attribution of the npm cluster itself.
The source says 13 npm packages deliver a stealer that harvests Chrome extension storage, a supply-chain risk for developers who install npm dependencies.