North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft.

According to JFrog, the packages “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core” mimic the legitimate “rollup-plugin-polyfill-node” project, down to the description, repository metadata, and

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched

Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched Researchers at Ledger’s Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a

Daisugi, the Japanese technique of growing trees out of other trees (2020)

Daisugi, the Japanese technique of growing trees out of other trees (2020) Source: Hacker News

Launch HN: Hoplite (YC S26) – Effortlessly deploy cloud coding agents

Launch HN: Hoplite (YC S26) – Effortlessly deploy cloud coding agents Source: Hacker News