Find notable cyber news and cases, enriched with sources, timelines, and signals.

WeaselBiscuit stealer delivered via 13 npm packages

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The WeaselBiscuit stealer was found in 13 npm packages, expanding supply-chain risk to developer environments and extension data theft. The malware is triggered by an npm import, pulls its payload from an Npoint dead drop, and executes in memory after resolving command-and-control configuration. It harvests Chrome extension storage across Windows, macOS, and Linux, and on Windows it can also log clipboard contents and keystrokes.

Related Happenings

Indexed-btree npm runtime malware activity

Malware Activity
H score24 First: 20.09.2026 17:11 Last: 20.09.2026 17:11 Sources 1

About this happening: The indexed-btree npm package is an ongoing malware activity that hides a loader in normal runtime code to evade supply-chain defenses and reach developer environments at...

Indexed-btree linked npm malware campaign

Campaign
H score26 First: 20.09.2026 17:11 Last: 20.09.2026 17:11 Sources 1

About this happening: The indexed-btree npm malware campaign expanded to nine additional packages linked to the same operation, widening exposure across the npm ecosystem. The packages impe...

StubMaker Windows information stealer delivered via RubyGems

Malware Activity
H score30 First: 18.08.2026 14:40 Last: 18.08.2026 14:40 Sources 1

About this happening: The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...

NullReceiver trojanized npm packages C2 via Ethereum recipient address

Malware Activity
H score3 First: 05.08.2026 16:41 Last: 05.08.2026 16:41 Sources 1

About this happening: NullReceiver is a malware activity that hides C2 infrastructure inside Ethereum recipient addresses, letting trojanized npm packages decode a server location from...

North Korean npm developer-targeting blockchain-C2 campaign

Campaign
H score41 First: 29.07.2026 07:20 Last: 29.07.2026 07:20 Sources 1

About this happening: An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote acces...

Timeline

  1. 18.09.2026 13:40 2 articles · 3d ago

    Researchers uncover 13 npm packages delivering WeaselBiscuit stealer

    Initial Disclosure

    Researchers uncovered 13 npm packages that deliver WeaselBiscuit, a previously undocumented JavaScript stealer. The packages trigger a loader via npm import, pull the payload from an Npoint dead drop, resolve command-and-control configuration, profile the compromised host, and harvest Chrome extension storage across Windows, macOS, and Linux; on Windows, operator commands can also log clipboard contents and keystrokes. OpenSourceMalware says the malware overlaps with BeaverTail and OtterCookie linked to Contagious Interview, but there is no definitive evidence yet for North Korea attribution.

    Show sources