Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
Summary
Hide ▲
Show ▼
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The staged malware can steal browser data, cryptocurrency wallets, files, and clipboard content while also enabling interactive control. The package set uses lookalike names and hidden install-time execution to slip past dependency review and security scanning. That combination turns routine package installation into a high-risk supply-chain compromise path.
Related Happenings
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Lucide proxy npm packages browser DDoS botnet
Malware Activity
H score31
First: 14.07.2026 10:08
Last: 14.07.2026 10:08
Sources 1
About this happening:
A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
Lucide proxy npm packages browser DDoS botnet
Malware ActivityAbout this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
@Injectivelabs/[email protected] wallet-stealing package
Malware Activity
H score30
First: 10.07.2026 20:29
Last: 10.07.2026 20:29
Sources 1
About this happening:
The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
@Injectivelabs/[email protected] wallet-stealing package
Malware ActivityAbout this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
Timeline
-
03.07.2026 19:07 2 articles · 13d ago
North Korea-linked npm packages impersonate rollup-plugin-polyfill-node
Initial DisclosureNorth Korea-linked threat actors used lookalike npm packages, including rollup-packages-polyfill-core and rollup-runtime-polyfill-core, to impersonate rollup-plugin-polyfill-node and stage malware that performs environment checks, pulls an encrypted payload from 216.126.236[.]244, and enables remote access and data theft on developer workstations and build machines. The package chain also uses swift-parse-stream, quirky-token, react-icon-svgs, and rollup-plugin-polyfill-connect as staged loaders, with JSONKeeper used to fetch and execute JavaScript malware.
Show sources
- North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets — thehackernews.com — 03.07.2026 19:07
- North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets — thehackernews.com — 03.07.2026 19:07