WeaselBiscuit: 13 npm packages harvest Chrome extension storage (Contagious Interview overlap noted)
The Hacker News (18 September 2026), citing OpenSourceMalware / Paul McCarty, reports a cluster of 13 npm packages delivering WeaselBiscuit, a previously undocumented JavaScript stealer. Triggered on npm import (not a full RAT): resolves C2 from an Npoint URL, profiles the host, and harvests Chrome extension storage across Windows, macOS, and Linux — financially relevant for wallet-extension state and other extension-held secrets, without the crypto-drainer / InvisibleFerret secondary-payload features of BeaverTail-class tooling. Researchers note meaningful overlap with DPRK Contagious Interview / BeaverTail tooling but state there is no definitive operator-infrastructure or victimology attribution to WaterPlum/DPRK yet — keep distinct from the ACSC WaterPlum joint advisory already on the desk. Wire-only until OpenSourceMalware primary URL confirmed; primary_url is THN for this pass. Developers: audit unexpected npm deps; revoke compromised extension sessions; align with Contagious Interview interview-tool hygiene.
- Product
- npm packages → Chrome extension storage stealer (WeaselBiscuit)
- Versions
- n/a (malware; 13-package cluster per THN)
- Exploited in Australia?
- unknown
- Patch to
- Remove untrusted npm packages; rotate credentials/sessions in browser extensions; treat interview/coding take-home tooling as untrusted (same hygiene as Contagious Interview guidance)
Primary: The Hacker News — WeaselBiscuit npm stealer / 13 packages (18 Sep 2026) · OpenSourceMalware (researcher source cited by THN; confirm package list there)
