Find notable cyber news and cases, enriched with sources, timelines, and signals.

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
First reported
Last updated
Happening score
H score 16
1 unique sources, 1 articles

Summary

Hide ▲

Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The staged malware can steal browser data, cryptocurrency wallets, files, and clipboard content while also enabling interactive control. The package set uses lookalike names and hidden install-time execution to slip past dependency review and security scanning. That combination turns routine package installation into a high-risk supply-chain compromise path.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

Lucide proxy npm packages browser DDoS botnet

Malware Activity
H score31 First: 14.07.2026 10:08 Last: 14.07.2026 10:08 Sources 1

About this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

@Injectivelabs/[email protected] wallet-stealing package

Malware Activity
H score30 First: 10.07.2026 20:29 Last: 10.07.2026 20:29 Sources 1

About this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...

Timeline

  1. 03.07.2026 19:07 2 articles · 13d ago

    North Korea-linked npm packages impersonate rollup-plugin-polyfill-node

    Initial Disclosure

    North Korea-linked threat actors used lookalike npm packages, including rollup-packages-polyfill-core and rollup-runtime-polyfill-core, to impersonate rollup-plugin-polyfill-node and stage malware that performs environment checks, pulls an encrypted payload from 216.126.236[.]244, and enables remote access and data theft on developer workstations and build machines. The package chain also uses swift-parse-stream, quirky-token, react-icon-svgs, and rollup-plugin-polyfill-connect as staged loaders, with JSONKeeper used to fetch and execute JavaScript malware.

    Show sources