SECURITY·중요도 8·2026. 09. 18.·The Hacker News

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

── KO ──────────────────

WeaselBiscuit라는 악성이 13개의 npm 패키지를 통해 확산되고 있습니다.

사이버 보안 연구원들이 WeaselBiscuit라는 새로운 자바스크립트 스틸러를 발견했습니다. 이 악성코드는 13개의 npm 패키지를 통해 확산되며, 한국의 특정 해킹 캠페인과 연관된 두 가지 악성코드와 기능적으로 유사점을 보입니다. 사용자의 크롬 확장 프로그램 저장소를 탈취하는 기능을 가지고 있습니다.


── EN ──────────────────

WeaselBiscuit malware spreads through 13 npm packages to steal Chrome extension data.

Cybersecurity researchers have identified a new JavaScript stealer called WeaselBiscuit. This malware is spreading through a cluster of 13 npm packages and exhibits functional overlaps with two malware strains linked to a specific hacking campaign associated with North Korea. It is designed to harvest storage related to Chrome extensions.

원문 보기 →목록으로