$ techbeacon▋
CVE & Exploits

Supply‑Chain Breach: 13 npm Modules Distribute New “WeaselBiscuit” Chrome Extension Data Stealer

Supply‑Chain Breach: 13 npm Modules Distribute New “WeaselBiscuit” Chrome Extension Data Stealer

Cybersecurity analysts have identified a coordinated campaign that leverages thirteen separate npm packages to deliver a previously unknown JavaScript malware family dubbed "WeaselBiscuit." The malicious code is designed to infiltrate users' browsers and exfiltrate data stored by Chrome extensions, marking a notable expansion of supply‑chain threats targeting the JavaScript ecosystem.

According to the OpenSourceMalware project, the WeaselBiscuit payload shares functional characteristics with two earlier malware strains, suggesting that its authors borrowed proven techniques while adding novel components. Once a compromised package is installed, the code executes in the victim's environment, scans for Chrome extension storage files, and transmits the harvested information to remote servers under the attackers' control.

The incident underscores the persistent risk posed by third‑party dependencies in modern web development. npm, the default package registry for Node.js, hosts millions of modules, many of which are maintained by small teams or individual contributors. Attackers exploit this landscape by publishing malicious versions of legitimate libraries or inserting backdoors into existing packages, relying on developers' trust and the speed of automated builds to spread the payload widely.

Initial coverage of the breach appeared on The Hacker News, which highlighted the rapid propagation of the infected modules across multiple open‑source projects. OpenSourceMalware’s analysis provides technical details, including code signatures and command‑and‑control endpoints, to aid security teams in detecting and removing the threat. Experts advise developers to audit their dependency trees, employ lock‑file verification, and monitor for unexpected network traffic from build environments.

The discovery of WeaselBiscuit adds to a growing list of supply‑chain attacks that have targeted high‑profile software in recent years, reinforcing calls for stronger governance of open‑source components. As the npm ecosystem continues to evolve, both maintainers and users will need to adopt more rigorous verification practices to mitigate the risk of similar intrusions in the future.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related