LIVE · cybersecurity feed
Live wire
security

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "rollup-packages-polyfi

zeroday.news · 29d ago

Security researchers have uncovered a new campaign involving malicious npm packages designed to steal sensitive information from developers. These packages, attributed to threat actors associated with North Korea, are disguised as legitimate Rollup polyfill tools.

The discovered packages include names such as "rollup-packages-polyfi," "rollup-plugin-polyfill," and "rollup-polyfill." Their primary objective is to establish remote access to compromised systems and exfiltrate valuable data.

Upon installation, these malicious packages execute a script that fetches and runs additional malicious code from a remote server. This secondary payload is responsible for collecting and transmitting sensitive information back to the attackers.

The types of data targeted include developer secrets such as API keys, authentication tokens, and potentially other credentials stored within the development environment. This information could then be used for further malicious activities, including unauthorized access to cloud services, code repositories, or other sensitive systems.

The campaign specifically targets developers using npm, the default package manager for Node.js. By impersonating essential development tools like Rollup polyfills, the attackers aim to trick developers into unknowingly installing the malicious code into their projects.

Rollup is a module bundler for JavaScript, commonly used in modern web development to package code for efficient delivery. Polyfills are used to provide modern functionality in older JavaScript environments that do not natively support it. The malicious packages leverage the trust associated with these development tools to gain a foothold.

While the specific details of the remote server infrastructure and the full extent of the data exfiltration are still under investigation, the discovery highlights a growing trend of supply chain attacks targeting the software development ecosystem. Developers are a prime target due to their access to valuable credentials and intellectual property.

As a general security measure, developers are advised to exercise extreme caution when installing any npm packages, especially those that appear to be related to common tools or utilities. It is recommended to verify the authenticity and reputation of packages before adding them to projects, review package dependencies, and consider using security scanning tools to detect malicious code.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.