CuraSec

Act active

WeaselBiscuit JS Stealer Delivered via 13 Malicious npm Packages

2026-09-18 14:58 UTC · The Hacker News · read the source ↗ #npm-supply-chain#dprk#stealer-malware
  • Engineer — Act: Supply-chain compromise via npm is directly in scope — audit your package-lock.json and dependency trees for these 13 named packages immediately, remove any matches, and rotate credentials and tokens accessible from affected developer workstations or CI runners.
  • SOC/IR — Plan: The overlap with DPRK’s Contagious Interview campaign (BeaverTail TTPs) gives a detection anchor — build or tune rules for suspicious npm package installs on developer endpoints and Chrome extension storage access patterns consistent with credential harvesting.
  • Leader — Learn: A DPRK-linked supply-chain operation targeting developer npm environments is worth adding to the developer-risk section of the risk register, but no systemic or vendor-level exposure is confirmed yet — monitor for follow-on reporting.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.