WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Malware is Spreading Through Popular Developer Tool, Putting Millions of Chrome Extension Users at Risk

A sophisticated malware campaign has been discovered spreading through 13 popular npm packages, compromising millions of users who rely on these developer tools. WeaselBiscuit Stealer, as it’s being called, infiltrates Chrome extensions by exploiting a vulnerability in the way these packages handle user data.

The attack is particularly insidious because it takes advantage of the trust that developers place in widely used libraries and frameworks. npm (Node Package Manager) is one of the largest package managers in the world, with over 12 million packages available for download. WeaselBiscuit Stealer has successfully infiltrated a small fraction of these, targeting users who have installed Chrome extensions related to development, productivity, or security.

The malware works by intercepting user data stored within Chrome extension APIs, which can include sensitive information such as login credentials and encryption keys. Once the attackers gain access to this data, they can use it to launch more targeted attacks on individual users, or even pivot into larger networks. The fact that WeaselBiscuit Stealer is able to spread through reputable npm packages makes it all the more difficult for developers to detect.

The 13 compromised packages are a mix of old and popular projects, with some having been updated as recently as last month. While the attackers seem to have targeted Chrome extension users specifically, it’s possible that WeaselBiscuit Stealer could adapt to other platforms in the future. The malware’s creators appear to be highly organized and motivated, suggesting that this campaign is part of a larger effort.

This attack serves as a stark reminder that even trusted tools can pose security risks if not properly maintained or used with caution. Developers who rely on npm packages should review their dependencies regularly for signs of tampering or unusual behavior. Meanwhile, users who have installed Chrome extensions from the past few months should consider updating their browsers and reviewing their account settings to minimize potential exposure.

In the face of this evolving threat landscape, it’s essential that we prioritize security awareness and vigilance in our digital endeavors. By being mindful of the tools we use and the data they handle, we can reduce the likelihood of falling victim to sophisticated malware campaigns like WeaselBiscuit Stealer.


Source: The Hacker News — 2026-09-18