Act
active
WeaselBiscuit JS Stealer Delivered via 13 Malicious npm Packages
- Engineer — Act: Supply-chain compromise via npm is directly in scope — audit your package-lock.json and dependency trees for these 13 named packages immediately, remove any matches, and rotate credentials and tokens accessible from affected developer workstations or CI runners.
- SOC/IR — Plan: The overlap with DPRK’s Contagious Interview campaign (BeaverTail TTPs) gives a detection anchor — build or tune rules for suspicious npm package installs on developer endpoints and Chrome extension storage access patterns consistent with credential harvesting.
- Leader — Learn: A DPRK-linked supply-chain operation targeting developer npm environments is worth adding to the developer-risk section of the risk register, but no systemic or vendor-level exposure is confirmed yet — monitor for follow-on reporting.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.