Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
The Hacker News
1 month ago

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

By info@thehackernews.com (The Hacker News)

Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" mimic the legitimate "rollup-plugin-polyfill-node" project, down to the description, repository metadata, and

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.