A sophisticated campaign, attributed to North Korean state-sponsored threat actors, has been uncovered, involving a new wave of malicious npm packages designed to masquerade as legitimate Rollup polyfill tooling. This elaborate scheme aims to establish remote access and facilitate extensive data theft from unsuspecting developers and organizations. The discovery underscores the escalating threat of software supply chain attacks and the persistent efforts of advanced persistent threat (APT) groups to infiltrate critical development environments.
The Modus Operandi: A Deep Dive into the Malicious Packages
Cybersecurity researchers at JFrog have identified several npm packages that exhibit hallmarks of this North Korean-linked activity. Central to this campaign are "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core," which meticulously mimic the legitimate "rollup-plugin-polyfill-node" project. The attackers went to considerable lengths to replicate not only the functional description but also repository metadata and the overall package structure, making these malicious components appear highly credible during a cursory review. This level of mimicry is a hallmark of sophisticated supply chain attacks, designed to exploit trust in widely used open-source ecosystems.
The deceptive naming strategy plays a crucial role in the efficacy of the attack. By placing these lookalike packages within the "rollup," "polyfill," "core," and "node" naming space, threat actors engineered them to blend seamlessly with existing dependencies, making them difficult to detect during routine dependency checks. Developers, often under pressure and working with numerous dependencies, might easily overlook the subtle discrepancies, assuming the packages are part of the legitimate Rollup ecosystem.
Beyond these primary packages, the campaign also involved at least four other related packages, which have since been removed from the npm registry following their identification. This rapid removal indicates active monitoring and response by the npm security team, though the transient nature of these malicious uploads highlights the continuous cat-and-mouse game between attackers and platform defenders.
A key observation in this campaign is the multi-stage infection process. "rollup-packages-polyfill-core" is designed to install and load a secondary package named "swift-parse-stream," while "rollup-runtime-polyfill-core" performs a similar action with "quirky-token." In a parallel infection chain, "react-icon-svgs" was found to install "rollup-plugin-polyfill-connect" as a second-stage component. This layered approach adds complexity to the attack, allowing the initial package to appear less suspicious while offloading the actual malicious payload to a subsequent stage. This technique also provides a degree of modularity, enabling the attackers to update or swap out payloads without needing to modify the initial infection vector.
Attribution and Broader Context: North Korea’s Persistent Threat

The attribution of this campaign to North Korean threat actors is based on a convergence of factors, including the specific tactics, techniques, and procedures (TTPs) employed, as well as the nature of the payloads. North Korea’s state-sponsored hacking groups, collectively known as the Lazarus Group, are notorious for their sophisticated cyber espionage, sabotage, and financially motivated operations. These groups frequently target high-value individuals and organizations, often with a focus on defense, cryptocurrency, and technology sectors, to support the regime’s strategic objectives and illicit funding generation.
Software supply chain attacks have become an increasingly popular vector for state-sponsored actors. By injecting malicious code into widely used software components or libraries, attackers can compromise a vast number of downstream users without needing to directly target each victim. This method offers a high return on investment for threat groups, as a single successful compromise can open doors to numerous targets within diverse industries. The npm registry, being a critical repository for JavaScript packages, presents an attractive target due to its pervasive use across modern web development. Compromising npm packages allows attackers to effectively backdoor thousands, if not millions, of applications and development environments globally.
Chronology of Deception: A Pattern of Malicious Activity
This recent discovery is not an isolated incident but rather a continuation of a sustained campaign by North Korean threat actors targeting the npm ecosystem with polyfill impersonations. Cybersecurity firms have been tracking these activities for some time, revealing a consistent pattern of sophisticated deception.
In April 2026, Panther, another prominent cybersecurity research firm, extensively detailed a significant npm campaign linked to North Korea. This earlier operation involved the publication of an astonishing 108 malicious npm packages across 261 versions, designed to deliver malware families known as BeaverTail and OtterCookie. These malware variants are closely associated with "Contagious Interview," a term often used to describe specific North Korean operations. Among the packages identified in that campaign was "rollup-plugin-polyfill-route," which was published on March 20, 2026. The striking similarity in the targeting of Rollup polyfill tools across these campaigns strongly suggests a coordinated and persistent strategy by the same threat actor group. The use of similar naming conventions and the focus on developer-centric tools further cement this linkage, indicating a well-honed playbook.
The repeated targeting of polyfill tools is strategically sound for attackers. Polyfills are pieces of code that provide modern functionality on older browsers or environments that do not natively support it. They are essential for ensuring broad compatibility of web applications. Rollup, on the other hand, is a module bundler for JavaScript, which compiles small pieces of code into larger, more complex applications. Both are fundamental components in many web development workflows, making them ideal targets for injecting malicious code that can then propagate widely.
The Anatomy of the Payload: Remote Access and Data Exfiltration
The technical execution of the attack begins with a Base64-encoded npm install command embedded within the initial malicious packages ("rollup-packages-polyfill-core" or "rollup-runtime-polyfill-core"). This hidden command triggers the installation of the second-stage packages, "swift-parse-stream" or "quirky-token." These secondary packages, deceptively presented as benign SVG sanitization utilities, then reach out to a JSONKeeper URL to retrieve a JSON object. Crucially, a specific "model" field within this JSON object contains JavaScript malware, which is then executed using the eval function.

Before executing its full malicious capabilities, the JavaScript code incorporates several checks to avoid detection. It specifically looks for indicators of cloud development environments, sandboxes, serverless runtimes, and analysis infrastructure. This environmental reconnaissance is a common evasion technique employed by sophisticated malware to prevent researchers from analyzing its full functionality and to ensure it only activates in target-rich, genuine developer environments. If these checks are passed, the malware proceeds to install additional necessary dependencies.
The next critical step involves the malware reaching out to an external command-and-control (C2) server, identified as 216.126.236[.]244, to fetch an encrypted JavaScript payload. This payload, once decrypted, acts as a loader for further malicious scripts, enabling a wide array of functionalities designed for comprehensive compromise and data exfiltration.
The capabilities of this final payload are extensive and alarming:
- Remote Access and Control: It facilitates interactive terminal sessions, allowing attackers to execute arbitrary commands on the compromised host. This includes the ability to capture screenshots, terminate processes, and, specifically for Windows systems, control mouse movements, clicks, scrolling, keyboard presses, and hotkeys. This granular control is achieved through the integration of the "@nut-tree-fork/nut-js" package, a legitimate library often used for automation, but here weaponized for malicious purposes.
- Data Theft: The malware is designed to systematically steal sensitive data from various sources. This includes credentials and other valuable information from web browsers and cryptocurrency wallets. It also meticulously collects files matching specific extensions, likely targeting configuration files, private keys, and project data.
- Clipboard Surveillance: The malware periodically captures clipboard content, a tactic often used to steal passwords, API keys, or other sensitive information copied by the user.
These features exhibit significant overlap with those observed in previous North Korean malware, particularly OtterCookie. The use of "@nut-tree-fork/nut-js" for remote control was also noted in "express-session-js," another malicious package detailed by SafeDep in April 2026, further reinforcing the attribution to this persistent threat actor. The file collector component is particularly insidious, as it specifically targets editor history associated with popular development tools like Microsoft Visual Studio Code, Windsurf, and Cursor. Furthermore, it seeks out developer and AI tool configurations, including those for AWS, Microsoft Azure, Google Gemini, Anthropic Claude, Foundry, SSH, and Z shell (Zsh). This targeted data collection highlights the attackers’ interest in intellectual property, cloud credentials, and access to advanced AI development resources, reflecting a clear strategic intelligence gathering objective.
Why Developers are Prime Targets: The Lure of Sensitive Environments
JFrog aptly points out the critical vulnerability that developer workstations and continuous integration/continuous deployment (CI/CD) pipelines represent. "Rollup plugins are commonly loaded from local configuration files, developer workstations, and CI jobs," the cybersecurity firm noted. These environments are treasure troves of sensitive assets, including source code, npm tokens, Git credentials, cloud keys, SSH keys, browser data, and various project secrets.
The payload’s broad capabilities—encompassing both data collection and remote control—make it particularly potent for targeting these environments. Once the later stages of the malware execute, attackers gain the ability to not only exfiltrate critical information but also to maintain persistent access, pivot to other systems, or inject further malicious code into projects. This makes developer workstations and build machines highly attractive targets for espionage and sabotage, as a successful compromise can lead to intellectual property theft, supply chain poisoning, or direct access to cloud infrastructure. The potential for damage is immense, ranging from direct financial losses to long-term reputational harm and erosion of trust in the software ecosystem.
Industry Response and Broader Supply Chain Concerns

This disclosure from JFrog coincides with a flurry of activity from other cybersecurity firms and researchers highlighting similar software supply chain attacks. Checkmarx, SafeDep, and AWS security researcher Chi Tran have all reported on efforts to poison open-source package repositories and steal valuable data. These parallel discoveries underscore a broader, escalating trend where attackers are increasingly leveraging the open-source software ecosystem as an attack vector.
The swift removal of the malicious packages from the npm registry is a positive step, demonstrating the proactive measures taken by platform providers. However, the ephemeral nature of these packages and the continuous re-emergence of new variants highlight the ongoing challenge. Organizations and individual developers cannot solely rely on platform providers to catch every malicious upload.
Mitigation and Best Practices: Fortifying the Software Development Lifecycle
In light of these persistent threats, users and organizations must adopt robust security practices to protect their development environments and software supply chains. The advice from security experts is clear and actionable:
- Remove Malicious Packages: Immediately remove any of the aforementioned packages—or any suspicious dependencies—from workstations and project dependencies.
- Assume Compromise and Rotate Credentials: Given the remote access and data theft capabilities, it is imperative to assume compromise if any of these packages were installed. All credentials, including npm tokens, Git credentials, SSH keys, and cloud provider API keys, must be rotated immediately. This includes resetting passwords for web browsers and cryptocurrency wallets.
- Block Malicious Egress Channels: Implement network security measures to block communication with known malicious IP addresses and domains, such as
216.126.236[.]244. This can help prevent data exfiltration and C2 communication even if a system is compromised. - Enable Dependency Scanning in CI/CD Pipelines: Integrate automated dependency scanning tools into CI/CD pipelines. These tools can help flag newly published or suspicious packages, identify known vulnerabilities, and detect unexpected changes in package behavior or metadata. Proactive scanning is crucial to catch threats before they become embedded in production code.
- Exercise Due Diligence: Always vet new dependencies, especially those that are less popular or have unclear origins. Check for signs of legitimacy such as active maintenance, community engagement, and reputable authors.
- Principle of Least Privilege: Apply the principle of least privilege to development environments and user accounts. Limit permissions to only what is necessary for a given task, reducing the impact of a potential compromise.
- Endpoint Detection and Response (EDR): Deploy robust EDR solutions on developer workstations to detect and respond to suspicious activities, even if they bypass traditional antivirus.
- Supply Chain Security Best Practices: Implement comprehensive software supply chain security frameworks, including reproducible builds, integrity checks, and signing of artifacts, to ensure the authenticity and integrity of all software components.
The Enduring Challenge
The ongoing campaign by North Korean threat actors against the npm ecosystem underscores the critical and evolving nature of software supply chain security. As development processes become increasingly reliant on open-source components, the attack surface expands, creating new opportunities for sophisticated adversaries. The meticulous mimicry, multi-stage payloads, and targeted data exfiltration capabilities demonstrated in this campaign highlight the advanced techniques employed by state-sponsored groups. Protecting the software supply chain requires a multi-faceted approach, combining vigilant monitoring, robust technical controls, and continuous education for developers and security teams alike. The fight against these persistent threats is a continuous journey, demanding constant adaptation and collaboration across the cybersecurity community.
