logo

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

ID: f4756d11-de83-54c7-bada-06288f89c779

STIX ID: report--f4756d11-de83-54c7-bada-06288f89c779

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-07-03

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Threat actors tied to North Korea uploaded malicious npm packages masquerading as Rollup polyfill tooling that install second-stage payloads from remote hosts; the multi-stage JavaScript malware provides remote-access and data-theft capabilities (credential and wallet theft, file collection, screenshots, remote mouse/keyboard control) and specifically targets developer workstations and CI environments. The report lists affected package names, observed infrastructure (including IPs), similarities to prior Lazarus-linked campaigns, and recommends removing packages, assuming compromise, rotating credentials, blocking egress, and enabling dependency scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.