logo

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

ID: 7e392af0-eee6-5da5-b658-ed75758921d5

STIX ID: report--7e392af0-eee6-5da5-b658-ed75758921d5

Feed Name: CosmicBytez Labs

Threat Score
72/100

Date Published: 2026-09-18

Date Updated: 2026-09-18

...
...

Researchers discovered a JavaScript stealer called WeaselBiscuit hidden in 13 malicious npm packages that exfiltrates Chrome extension LevelDB storage (targeting crypto wallets and sensitive extension state) across Windows, macOS, and Linux, logs keystrokes/clipboard on Windows, and communicates with a C2 at 103.170.217.184:8787; indicators and C2 patterns suggest links to the Contagious Interview campaign cluster, and the report includes remediation and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.