
highMalware
WeaselBiscuit JavaScript Stealer Discovered in 13 Malicious npm Packages
Researchers have identified a cluster of 13 npm packages distributing a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The malware targets Chrome extension storage to harvest credentials, tokens, and other sensitive data. Analysis indicates functional overlaps with BeaverTail and another strain associated with the Democratic People's Republic of Korea's Contagious Interview campaign, though attribution remains tentative.
The Hacker News1 min read