← All stories
● Covered by 1 source · 1 reportHigh impact

Malicious npm Packages Linked to North Korea Target Developers' Secrets

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Malicious npm packages impersonate Rollup polyfills for data theft.
  • Packages removed from npm include 'rollup-packages-polyfill-core'.
  • Mimicked packages use hidden execution to retrieve malware.

Overview of the Malicious npm Packages

A group of malicious npm packages, tied to North Korean threat actors, has been discovered masquerading as Rollup polyfill tools. These packages, specifically "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core," closely resemble the legitimate "rollup-plugin-polyfill-node," including similarities in description and metadata.

Details of the Malicious Campaign

Security firm JFrog analyzed these packages and noted their cunning placement within the npm ecosystem, making them look believable during quick dependency audits. The malicious packages have been linked with others such as "quirky-token," "react-icon-svgs," "rollup-plugin-polyfill-connect," and "swift-parse-stream," all of which have been removed from the npm registry.

Technical Mechanisms of the Attack

The packages are designed to install additional dependencies that act as second-stage malware installers. For instance, executing "rollup-packages-polyfill-core" leads to loading "swift-parse-stream," while "rollup-runtime-polyfill-core" retrieves "quirky-token." These secondary packages are crafted to appeal as SVG utilities but facilitate the execution of harmful JavaScript from external URLs.

Historical Context of Similar Threats

This incident is not isolated, as previous attacks linked to North Korea have involved similar strategies. In April 2026, 108 malicious npm packages, including "rollup-plugin-polyfill-route," were identified as part of a campaign delivering malware like BeaverTail and OtterCookie.

Implications for the Developer Community

The sophistication and persistence of these tactics highlight the ongoing risks developers face from state-sponsored cyber activities. Developers must exercise caution in reviewing dependencies to mitigate potential exploitation of sensitive data.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

North Korea-linked malicious npm packages masquerade as Rollup polyfills, enabling data theft. The packages mimic legitimate ones to facilitate remote access to sensitive developer information, highlighting ongoing threats against the tech development community.