By Interestana AI Editorial — AI-drafted, human-overseen. How we report
WeaselBiscuit Stealer Infects 13 npm Packages

Cybersecurity researchers have identified a new threat actor distributing a previously undocumented JavaScript stealer, codenamed WeaselBiscuit, through 13 npm packages. OpenSourceMalware, a cybersecurity research group, reported on March 12, 2024, that these npm packages were designed to harvest sensitive data from Chrome browser extensions. The malware family exhibits functional similarities to two previously known malware strains, BeaverTail and another unnamed strain, both of which have been linked to the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign. This discovery highlights a sophisticated supply chain attack vector targeting the widely used Node Package Manager (npm) ecosystem.
The WeaselBiscuit stealer's primary objective is to exfiltrate data stored by Chrome extensions, which can include highly sensitive information such as login credentials, session cookies, and financial details. By embedding the malicious code within seemingly legitimate npm packages, attackers can leverage the trust developers place in these open-source components to distribute their malware widely. Developers who unknowingly install these compromised packages risk having their systems and the data accessed by their extensions compromised. The researchers noted that the malware's functionality overlaps with known DPRK-linked malware, suggesting a potential state-sponsored or state-affiliated operation. This connection is significant as it points to advanced persistent threat (APT) tactics being employed within the open-source software development landscape.
The npm ecosystem is a critical component of modern software development, with millions of packages available for developers to use. The compromise of even a small number of these packages can have a far-reaching impact, as the malicious code can be distributed to a vast number of downstream users. The WeaselBiscuit campaign demonstrates a clear intent to exploit this trust. The researchers are actively monitoring the situation and have alerted the npm security team to facilitate the removal of the malicious packages. However, the dynamic nature of such threats means that vigilance and robust security practices are paramount for developers and organizations relying on open-source software. The specific details of the functional overlaps with BeaverTail and the other DPRK-linked malware are still under investigation, but the implication is that the threat actor is leveraging or adapting existing, sophisticated malware capabilities.
The discovery of WeaselBiscuit underscores the growing threat of supply chain attacks in the software development world. These attacks target the software supply chain—the processes, people, and technologies involved in creating and delivering software—to compromise systems. By injecting malicious code into widely used libraries or tools, attackers can gain access to a broad range of targets. The DPRK has been previously implicated in various cybercriminal activities, including financial theft and espionage, often through sophisticated malware campaigns. The attribution to DPRK-linked campaigns suggests that the WeaselBiscuit stealer may be part of a larger, ongoing effort by the nation-state to gather intelligence or financial resources. The research by OpenSourceMalware serves as a crucial alert to the cybersecurity community, emphasizing the need for continuous monitoring of the npm registry and enhanced security protocols for software development pipelines.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.