Last updated 2 weeks ago
JFrog, a technology company, disclosed on July 5, 2026, that threat actors with ties to North Korea have been linked to two malicious npm packages, "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core". These packages mimic the legitimate "rollup-plugin-polyfill-node" project, down to the description and repository metadata, to facilitate remote access and data theft. No specific discovery date or number of affected records was provided.
The attack vector is supply chain, as the malicious packages were published to the npm registry, targeting developers who might inadvertently install them. The packages masquerade as Rollup polyfill tooling, enabling remote access and exfiltration of developer secrets. The threat actor is attributed to North Korea, though no specific group name or TTPs were detailed in the article.
No post-incident developments such as regulatory actions, litigation, ransom payments, or remediation milestones were reported in the article.
Malicious npm packages masquerading as legitimate Rollup polyfill tooling to facilitate remote access and data theft
This supply chain attack targeting JFrog and the npm ecosystem underscores the need for rigorous package verification and integrity checks. Developers should implement automated scanning for known malicious packages and enforce strict dependency review processes to prevent installation of counterfeit tooling. The incident highlights the importance of monitoring for typosquatting and metadata mimicry in open-source registries.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor