AUTO-UPDATED

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

North Korean threat actors are distributing malicious npm packages disguised as legitimate Rollup polyfill tools to facilitate remote access, credential theft, and data exfiltration from developer workstations.

Key Points

  • Researchers at JFrog identified six malicious npm packages, including "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core," that mimic legitimate development tools.
  • The malware uses a multi-stage execution process to bypass security sandboxes and fetch encrypted payloads from external servers.
  • Once active, the scripts enable remote terminal access, capture screenshots, and steal sensitive data from browsers, cryptocurrency wallets, and developer configuration files.
  • The campaign specifically targets credentials for services like AWS, Microsoft Azure, Google Gemini, and Anthropic Claude, as well as SSH and Git keys.
  • All identified malicious packages have been removed from the npm registry, but users are advised to rotate credentials and audit their development environments.

Why it Matters

This campaign highlights the ongoing risk of software supply chain attacks targeting developers, who often possess high-level access to sensitive corporate infrastructure and cloud secrets. By compromising build environments, attackers can gain persistent access to proprietary source code and critical production credentials, posing a significant threat to organizational security.
Internet Published by info@thehackernews.com (The Hacker News)
Read original