North Korean threat actors are distributing malicious npm packages disguised as legitimate Rollup polyfill tools to facilitate remote access, credential theft, and data exfiltration from developer workstations.
Key Points
- Researchers at JFrog identified six malicious npm packages, including "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core," that mimic legitimate development tools.
- The malware uses a multi-stage execution process to bypass security sandboxes and fetch encrypted payloads from external servers.
- Once active, the scripts enable remote terminal access, capture screenshots, and steal sensitive data from browsers, cryptocurrency wallets, and developer configuration files.
- The campaign specifically targets credentials for services like AWS, Microsoft Azure, Google Gemini, and Anthropic Claude, as well as SSH and Git keys.
- All identified malicious packages have been removed from the npm registry, but users are advised to rotate credentials and audit their development environments.