WeaselBiscuit stealer delivered via 13 npm packages
Malware Activity
Summary
Hide ▲
Show ▼
The WeaselBiscuit stealer was found in 13 npm packages, expanding supply-chain risk to developer environments and extension data theft. The malware is triggered by an npm import, pulls its payload from an Npoint dead drop, and executes in memory after resolving command-and-control configuration. It harvests Chrome extension storage across Windows, macOS, and Linux, and on Windows it can also log clipboard contents and keystrokes.
Related Happenings
StubMaker Windows information stealer delivered via RubyGems
Malware Activity
H score30
First: 18.08.2026 14:40
Last: 18.08.2026 14:40
Sources 1
About this happening:
The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...
StubMaker Windows information stealer delivered via RubyGems
Malware ActivityAbout this happening: The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...
NullReceiver trojanized npm packages C2 via Ethereum recipient address
Malware Activity
H score3
First: 05.08.2026 16:41
Last: 05.08.2026 16:41
Sources 1
About this happening:
NullReceiver is a malware activity that hides C2 infrastructure inside Ethereum recipient addresses, letting trojanized npm packages decode a server location from...
NullReceiver trojanized npm packages C2 via Ethereum recipient address
Malware ActivityAbout this happening: NullReceiver is a malware activity that hides C2 infrastructure inside Ethereum recipient addresses, letting trojanized npm packages decode a server location from...
North Korean npm developer-targeting blockchain-C2 campaign
Campaign
H score41
First: 29.07.2026 07:20
Last: 29.07.2026 07:20
Sources 1
About this happening:
An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote acces...
North Korean npm developer-targeting blockchain-C2 campaign
CampaignAbout this happening: An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote acces...
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Timeline
-
18.09.2026 13:40 2 articles · 2h ago
Researchers uncover 13 npm packages delivering WeaselBiscuit stealer
Initial DisclosureResearchers uncovered 13 npm packages that deliver WeaselBiscuit, a previously undocumented JavaScript stealer. The packages trigger a loader via npm import, pull the payload from an Npoint dead drop, resolve command-and-control configuration, profile the compromised host, and harvest Chrome extension storage across Windows, macOS, and Linux; on Windows, operator commands can also log clipboard contents and keystrokes. OpenSourceMalware says the malware overlaps with BeaverTail and OtterCookie linked to Contagious Interview, but there is no definitive evidence yet for North Korea attribution.
Show sources
- WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage — thehackernews.com — 18.09.2026 13:40
- WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage — thehackernews.com — 18.09.2026 13:40