North Korea-linked npm packages imitate Rollup polyfills to exfiltrate data
Source headline: North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Intelligence Summary
JFrog identified malicious npm packages tied to North Korea that impersonate Rollup polyfill tooling. The packages “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core” are designed to closely match a legitimate Rollup polyfill plugin’s metadata. If installed, they can provide remote access capabilities and steal developer secrets. The threat specifically targets the JavaScript build ecosystem where npm dependencies are routinely added. Developers and maintainers should audit dependency provenance, review package contents, and avoid installing lookalike modules.
Recommended Action
Inventory where JFrog runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.