As cited
Copy frozen at (site build).
threat intel
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
North Korea-linked threat actors have published malicious npm packages disguised as Rollup polyfill tools to compromise developer environments and steal sensitive data. The packages mimicked legitimate Rollup polyfill projects in name, description, and metadata to evade detection. JFrog identified the campaign targeting developers through the popular npm package registry.
Why it matters: Developers using or installing these packages risk credential theft, source code exfiltration, and supply chain compromise; immediate verification of installed packages and dependencies is warranted.
- Source published
- First seen by Cybersecurity Tracker