WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
ID: 7e392af0-eee6-5da5-b658-ed75758921d5
STIX ID: report--7e392af0-eee6-5da5-b658-ed75758921d5
Feed Name: CosmicBytez Labs
Threat Score
Researchers discovered a JavaScript stealer called WeaselBiscuit hidden in 13 malicious npm packages that exfiltrates Chrome extension LevelDB storage (targeting crypto wallets and sensitive extension state) across Windows, macOS, and Linux, logs keystrokes/clipboard on Windows, and communicates with a C2 at 103.170.217.184:8787; indicators and C2 patterns suggest links to the Contagious Interview campaign cluster, and the report includes remediation and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
