LIVE · cybersecurity feed
Live wire
Cisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEV
malware

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

zeroday.news ·

Cybersecurity researchers have uncovered a new JavaScript stealer, dubbed WeaselBiscuit, which is being distributed through 13 malicious npm packages. The stealer's primary objective is to exfiltrate data from Chrome extension storage. This discovery highlights an ongoing threat vector targeting developers and users within the JavaScript ecosystem.

The WeaselBiscuit stealer operates by targeting the storage mechanisms of Chrome extensions. While the specific technical details of its exfiltration method were not fully elaborated, such stealers typically leverage JavaScript’s ability to interact with browser APIs. This allows them to access data stored by extensions, which can include sensitive information like session tokens, API keys, cryptocurrency wallet seeds, or other confidential data depending on the extension's functionality and the data it manages. The malware's distribution via npm packages indicates a supply chain attack vector, where malicious code is injected into legitimate-looking or seemingly benign software components that developers then incorporate into their projects.

The 13 identified npm packages serve as the initial infection vector. Developers who integrate these packages into their applications or build processes would inadvertently introduce the WeaselBiscuit stealer into their environment. This type of compromise can affect both the developer's local machine and any applications built with the tainted packages, potentially spreading the malware further down the software supply chain to end-users. The exact mechanism of how the stealer is activated or deployed post-installation from the npm package was not detailed, but it commonly involves post-install scripts or obfuscated code within the package itself that executes during build time or runtime.

Mitigation for such supply chain attacks typically involves rigorous vetting of third-party dependencies. Developers are advised to scrutinize npm packages before integration, checking for signs of compromise such as low download counts for established functionality, recent changes in maintainership, or unusual permissions requests. Employing software composition analysis (SCA) tools can help identify known vulnerabilities and malicious packages. Furthermore, implementing strong security practices like least privilege, network segmentation, and regular security audits of development environments are crucial. For end-users, keeping browsers and extensions updated, and being cautious about the permissions granted to extensions, can help limit exposure.

Researchers at OpenSourceMalware noted functional overlaps between WeaselBiscuit and two other malware strains: BeaverTail and another unnamed strain. These strains have previously been associated with the Democratic People's Republic of Korea's (DPRK) "Contagious Interview" campaign. This potential link suggests a sophisticated and persistent threat actor group may be behind the development and deployment of WeaselBiscuit, indicating a targeted and potentially state-sponsored effort to compromise software supply chains and gather intelligence or financial gain.

The emergence of WeaselBiscuit underscores the persistent and evolving threat landscape within open-source software ecosystems. Attackers continue to leverage the trust placed in package managers like npm to distribute malware, targeting developers as a high-value entry point into organizations and end-user systems. The focus on Chrome extension storage highlights the increasing value of browser-based data for adversaries, ranging from personal information to corporate credentials. This incident serves as a reminder of the critical need for enhanced security measures throughout the software development lifecycle and continuous vigilance against novel attack techniques.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

Are AIs Still Struggling with CAPTCHAs?

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed,

vulnerability

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.

breach

Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal,

breach

98% of fraudulent hires have company credentials by the time they’re caught

A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO of HYPR. “Human intuition is not a security control. Sceptics might po

breach

Most WordPress pros still lack a breach recovery plan

Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators. Across the whole group, fewer than three in ten have a breach recovery plan. A recovery plan settles in advance

ai

The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era

AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maintain audit readiness as environments change daily.