{"id":1593,"date":"2026-07-03T16:59:56","date_gmt":"2026-07-03T16:59:56","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1593"},"modified":"2026-07-03T16:59:56","modified_gmt":"2026-07-03T16:59:56","slug":"north-korea-linked-npm-packages-mimic-rollup-polyfills-to-steal-developer-secrets","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1593","title":{"rendered":"North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj4otDF6_5qt7ZmrCLMXmx7sFXfY6RGHHI0BiGRcVkTqLo-l1VokprcvB7FhK5fJdL0j8Ds95uLQxiWKt2YYFV1N9K8WIL3lfONey4wBln2Vee4YTI_9z5_t-2VT1bZ17sEomQdONnVWEB3sc9lj13AJwdhbmn6CNlfx9Lwc7UNxg2C87xKFZPz5UL4lHJE\/s1700-e365\/npms-malware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft.<\/p>\n<p>According to JFrog, the packages \u00abrollup-packages-polyfill-core\u00bb and \u00abrollup-runtime-polyfill-core\u00bb mimic the legitimate \u00ab<a href=\"https:\/\/www.npmjs.com\/package\/rollup-plugin-polyfill-node\">rollup-plugin-polyfill-node<\/a>\u00bb project, down to the description, repository metadata, and package shape.<\/p>\n<p>\u00abThe lookalike packages place themselves in the same rollup, polyfill, core, and node naming space, which can look plausible during a quick dependency review,\u00bb JFrog <a href=\"https:\/\/research.jfrog.com\/post\/rollup-polyfill-masquerading\/\">said<\/a> in a technical write-up of the campaign.<\/p>\n<p>The campaign also involves four other packages, all of which have since been removed from the npm registry &#8211;<\/p>\n<ul>\n<li>quirky-token<\/li>\n<li>react-icon-svgs<\/li>\n<li>rollup-plugin-polyfill-connect<\/li>\n<li>swift-parse-stream<\/li>\n<\/ul>\n<p>What&#8217;s noteworthy here is that \u00abrollup-packages-polyfill-core\u00bb installs and loads \u00abswift-parse-stream,\u00bb while \u00abrollup-runtime-polyfill-core\u00bb installs and \u00abquirky-token.\u00bb In a similar fashion, \u00abreact-icon-svgs\u00bb has been found to install \u00abrollup-plugin-polyfill-connect\u00bb as a second stage.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe second-stage packages are near-identical SVG utilities that fetch a JSON object from JSONKeeper and eval the model field,\u00bb the cybersecurity company said. \u00abThis layered structure, together with the lookalike names, legitimate-looking metadata, hidden install-time execution, environment checks, and credential-theft\/remote-access payloads, is similar to previous North Korean Lazarus-linked npm campaigns.\u00bb<\/p>\n<p>It&#8217;s worth emphasizing here that this is not the first time North Korean threat actors have uploaded npm packages impersonating Rollup polyfill tools. In April 2026, Panther <a href=\"https:\/\/thehackernews.com\/2026\/06\/north-korean-hackers-are-turning.html#:~:text=A%20sustained,OtterCookie\">detailed a sustained npm campaign that involved publishing 108 malicious npm packages spanning 261 versions to deliver BeaverTail and OtterCookie, two known malware families linked to Contagious Interview. Among those packages was \u00abrollup-plugin-polyfill-route,\u00bb which was published on March 20, 2026.<\/p>\n<p>The starting point of the attack is a Base64-encoded npm install command for \u00abswift-parse-stream\u00bb (or \u00abquirky-token\u00bb) that&#8217;s concealed within \u00abrollup-packages-polyfill-core\u00bb (or \u00abrollup-runtime-polyfill-core\u00bb). The two second-stage packages are dressed up as SVG sanitization utilities, while reaching out to a JSON Keeper URL to retrieve and execute a JavaScript malware.<\/p>\n<p>The JavaScript code runs checks to avoid execution within cloud development environments, sandboxes, serverless runtimes, and analysis infrastructure. Past this gate, the malware installs the necessary dependencies and reaches out to an external server (\u00ab216.126.236[.]244\u00bb) to fetch an encrypted JavaScript payload.<\/p>\n<p>The decrypted payload then acts as a loader for additional scripts responsible for enabling remote access to the compromised host to support interactive terminal sessions, command execution, screenshot capture, process termination, Windows-only mouse movement, clicks, scrolling, keyboard presses, and hotkeys using the \u00ab@nut-tree-fork\/nut-js\u00bb package, as well as steal data from web browsers and cryptocurrency wallets, collect files matching specific extensions, and periodically capture clipboard content.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgjaD0uLDz_dKt6-_w73Qum-1xkqqY0RUUjmGxIcBNNNwVu0u6jr2z9SqNAoP2jdZRnSX_ITooC1EQRGPe70h0dHiuDYl8Gqwa98wur1fGVLKa0gDwr_ORLc0skbRl66QCXxZtR0l-6jCGMGzzcyhkHowryFdzo68h2gTb69C15R4MeKkvsO4HBb2bd7mCv\/s1700-e365\/polyfill.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgjaD0uLDz_dKt6-_w73Qum-1xkqqY0RUUjmGxIcBNNNwVu0u6jr2z9SqNAoP2jdZRnSX_ITooC1EQRGPe70h0dHiuDYl8Gqwa98wur1fGVLKa0gDwr_ORLc0skbRl66QCXxZtR0l-6jCGMGzzcyhkHowryFdzo68h2gTb69C15R4MeKkvsO4HBb2bd7mCv\/s1700-e365\/polyfill.png\" alt=\"\" border=\"0\" data-original-height=\"1204\" data-original-width=\"2636\"\/><\/a><\/div>\n<p>The features overlap with those of OtterCookie, with the use of \u00ab@nut-tree-fork\/nut-js\u00bb for remote mouse and keyboard control also observed in a package named \u00abexpress-session-js\u00bb that was detailed by SafeDep in April 2026. The file collector component has been found to specifically look for editor history associated with Microsoft Visual Studio Code, Windsurf, and Cursor, along with developer and AI tool configurations, such as AWS, Microsoft Azure, Google Gemini, Anthropic Claude, Foundry, SSH, and Z shell (Zsh).<\/p>\n<p>\u00abRollup plugins are commonly loaded from local configuration files, developer workstations, and CI jobs,\u00bb JFrog said. \u00abThese environments often have access to sensitive assets such as source code, npm tokens, Git credentials, cloud keys, SSH keys, browser data, and project secrets.\u00bb<\/p>\n<p>\u00abThe payload is also broader than a simple downloader. Once the later stages run, the attacker gains both collection and control capabilities. This makes the payload relevant to developer workstations and build machines, where API keys, SSH keys, wallet material, cloud credentials, and project secrets are often present.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqmM4NpfZsx4cw-HrXQlCjZQmrF8bYnmB23AmpOPi16kPNB9lvICjpdYEclxJwyQ9OE8GgzQ8aOEI68tRuxNqov0MHz2Sq8xEPiYWM3Js6FM5t2nm2JHWodmR7qVSot14ZtWVqQRQ6B88OnMaVxCPwRG7xGPoIIZxF6QAhWVhMkQfs11NjyNtHsGEUH4_q\/s728-e100\/sygnia-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The disclosure coincides with the discovery of multiple software supply chain attacks by Checkmarx, SafeDep, and AWS security researcher Chi Tran aimed at poisoning open-source package repositories and stealing valuable data &#8211;<\/p>\n<ul>\n<li>A cluster of at least <a href=\"https:\/\/checkmarx.com\/zero-post\/operation-navy-ghost-pyrogram-telegram-supplychain-attack\/\">eight trojanized \u00abpyrogram\u00bb forks<\/a> published by a threat actor operating under multiple identities between November 2025 and June 2026, including a hidden backdoor that grants them full remote control over any server running the infected PyPI package by running arbitrary Python code or shell commands sent by the attacker. The results of the command execution are exfiltrated via Telegram. The activity has been codenamed Operation Navy Ghost by Checkmarx.<\/li>\n<li>A cluster of <a href=\"https:\/\/safedep.io\/defi-infostealer-fake-arbitrage-bot-npm\/\">30 npm packages<\/a> mimicking Polymarket tooling and general mathematics libraries published by 10 npm maintainer accounts that targeted DeFi developers to deliver a JavaScript infostealer that reads crypto wallet vaults, browser credentials, SSH keys, AWS credentials, npm tokens, Docker configurations, shell history, and password manager databases.<\/li>\n<li>A cluster of <a href=\"https:\/\/safedep.io\/marketfront-dependency-confusion-campaign\/\">25 npm packages<\/a> published under the @marketfront scope by an npm account named \u00abmarketfront\u00bb that contains a postinstall credential harvester that reads 20 credential and secret files, including ~\/.ssh, ~\/.aws\/credentials, ~\/.kube\/config, ~\/.docker\/config.json, ~\/.npmrc, ~\/.netrc, ~\/.pgpass, ~\/.git-credentials, ~\/.env, and shell history, and exfiltrates the data.<\/li>\n<li>A Python package named \u00ab<a href=\"https:\/\/www.linkedin.com\/pulse\/credential-stealer-c2-backdoor-disguised-security-monitoring-chi-tran-opx2c\/\">security-alerts-sdk<\/a>\u00bb that claims to be a data breach-monitoring tool but harbors code to launch a backdoor that periodically polls an external server (\u00ab142.93.211[.]30:5000\u00bb) for commands and exfiltrates SSH private keys, AWS credentials, Docker\/npm\/PyPI\/git tokens, .env files, and browser credential databases to the same server.<\/li>\n<li>A cluster of <a href=\"https:\/\/www.linkedin.com\/pulse\/operation-friday-harvest-coordinated-npm-campaign-delivering-tran-lmjlc\/\">15 npm packages<\/a> published by a single threat actor operating under 13 npm scopes that triggers a postinstall JavaScript payload responsible for downloading and executing a Rust-compiled ELF binary hosted on GitHub, which then harvests a wide range of data from cryptocurrency wallets, web browsers, and other applications, including cloud provider tokens, SSH keys, messaging platform sessions, database client configurations, and developer credentials.<\/li>\n<li>An npm package named \u00ab<a href=\"https:\/\/www.linkedin.com\/pulse\/emitting-more-than-events-125k-downloads-malicious-npm-chi-tran-h0bff\/\">events-runtime<\/a>\u00bb that typosquats the \u00ab<a href=\"https:\/\/www.npmjs.com\/package\/events\">events<\/a>\u00bb package and conditionally spawns a cryptocurrency wallet stealer, exfiltrates host reconnaissance data over Slack and Telegram, opens a bidirectional Slack command channel, and reads configuration and payload chunks from an Ethereum smart contract used as a dead drop resolver. The malicious logic is fired only when the event ID is \u00abeventId0.\u00bb<\/li>\n<li>An npm package named \u00ab<a href=\"https:\/\/www.linkedin.com\/pulse\/clean-npm-dirty-github-sneaky-new-supply-chain-pattern-chi-tran-l3sic\/\">o3forms<\/a>\u00bb that steals cloud service provider credentials, scans developer secrets and CI\/CD environments, performs internal network reconnaissance, and exfiltrates the data to an attacker-controlled Cloudflare Workers endpoint. \u00abThe attacker split the attack into a deliberately benign, registry-published package and a GitHub-pinned *-utils sub-dependency that carries both the install hooks and the actual malware,\u00bb Tran said. \u00abThis structure is designed specifically to defeat the static and lifecycle-script scanning that most registry-side and CI-side tooling relies on.\u00bb<\/li>\n<\/ul>\n<p>Users who have installed any of the aforementioned packages are advised to remove them from their workstations, assume compromise and rotate credentials, block the malicious egress channels, and enable dependency scanning in CI\/CD pipelines to flag newly published or suspicious packages.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1594,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[223,2330,2331,247,39,35,2333,2332,145,571],"class_list":["post-1593","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-developer","tag-korealinked","tag-mimic","tag-north","tag-npm","tag-packages","tag-polyfills","tag-rollup","tag-secrets","tag-steal"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1593"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1593\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1594"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}