logo

Lazarus-Linked npm Malware Masquerades as Rollup Polyfills

ID: 7248a858-a219-5b97-bc94-e5685d2bf613

STIX ID: report--7248a858-a219-5b97-bc94-e5685d2bf613

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-07-03

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

JFrog Security uncovered a supply-chain npm campaign where six lookalike Rollup polyfill packages install multi-stage malware that exfiltrates credentials and crypto-wallet data and provides remote-control capabilities; JFrog attributes the campaign to the Lazarus group by TTP similarity, noting staged loaders, sandbox evasion, and an active C2 (216.126.236.244) with some malicious packages still live at report time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.