WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

2026-09-18T13:24:01Z•3c02b3f6605cdcb27969ff1a2853b0fb5324d81f392c4f07a25659dd668ee7c5
CVE-2026-58704CVE-2026-76460CVE-2026-77179CVE-2026-81642CVE-2026-87886CVE-2026-89026ADB abuseAI securityAndroid malwareDDoS-for-hireDNS securityactive exploitationauthentication bypassbrowser extensionsdata breachinformation stealermacOSnpm malwarephishingprivilege escalationremote code executionstate-sponsored threat actorssupply chain compromisezero-day

What happened

The feed reports active exploitation of multiple critical vulnerabilities, including unauthenticated remote code execution in Check Point management servers and Issabel Framework, a Cisco ISE authentication-bypass zero-day, and an Unbound DNSSEC validator heap overflow enabling potential RCE. It also highlights npm-based JavaScript stealers, Android malware abusing ADB, state-sponsored backdoors, phishing and AI-assistant supply-chain attacks, major data exposure, and other emerging threats.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
3c02b3f6605cdcb27969ff1a2853b0fb5324d81f392c4f07a25659dd668ee7c5
Enrichment time
2026-09-18T13:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage · Baitaphish