[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbwsiECzWSw99I6aRr_tEuGKfniSNxYAcbdz8p_5Dsjw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"d9eff520-5e5a-4e97-aa9c-e43015c49932","malicious-npm-packages-impersonate-rollup-tools-to-target-developer-credentials","89cb84cd-06fd-4a1e-b3cb-2ba3fe8ad3c6","Malicious npm Packages Impersonate Rollup Tools to Target Developer Credentials","North Korea-linked threat actors published typosquatted npm packages designed to closely mimic legitimate Rollup polyfill libraries, exploiting developers' trust in the open-source ecosystem. Once installed, these packages silently downloaded and executed malicious JavaScript payloads capable of remote access, credential harvesting, and data exfiltration. This attack highlights the critical danger of unverified third-party dependencies, as a single compromised package can propagate malware across entire development pipelines and into production environments. The broader risk extends beyond individual developers — poisoned packages in CI\u002FCD workflows can lead to widespread breaches affecting end users and organizations at scale.","**Immediate actions:**\n- Audit all current npm dependencies for suspicious or lookalike package names by cross-referencing against known-good registries and checksums.\n- Remove and blacklist the identified malicious packages ('rollup-packages-polyfill-core', 'rollup-runtime-polyfill-core') from all development environments immediately.\n- Rotate any credentials, API keys, or secrets accessible from developer machines that may have had these packages installed.\n\n**Long-term improvements:**\n- Enforce the use of a private npm registry or artifact proxy (e.g., Artifactory, Nexus) that restricts installation to pre-vetted, approved packages only.\n- Implement a software composition analysis (SCA) tool in CI\u002FCD pipelines to automatically flag newly added or suspicious dependencies before build.\n- Establish a formal dependency review and approval process requiring security sign-off before any new open-source package is added to a project.\n\n**Detection measures:**\n- Enable runtime monitoring and behavioral analysis on developer workstations to detect unexpected outbound network connections or script executions triggered by package install hooks.\n- Configure alerts for npm postinstall scripts that attempt to download external payloads or spawn shell processes.\n- Subscribe to threat intelligence feeds and npm security advisories to receive timely warnings about newly identified malicious packages.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-3: Malicious Code Protection","NIST CSF DE.CM-8: Vulnerability Scans","NIST CSF ID.SC-4: Supply Chain Risk Assessment","SLSA Framework: Supply Chain Levels for Software Artifacts","OWASP A06:2021 – Vulnerable and Outdated Components","GDPR Article 32: Security of Processing (for organizations handling EU data)","published","2026-07-03T18:20:39.483041+00:00","2026-07-03T18:20:39.187+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fnorth-korea-linked-npm-packages-mimic.html","north-korea-linked-npm-packages-mimic-rollup-polyfills-to-steal-developer-secret-af919c","North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[43,49],{"id":44,"date":45,"edition":46,"title":47,"audio_url":48},"a9e701d2-0bfe-47a7-bb40-da332b8f6e3c","2026-07-05","afternoon","ThreatNoir Weekend Brief — July 5","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-05\u002Fthreatnoir-afternoon-brief-2026-07-05.mp3",{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"dc452d97-1c11-4442-942a-f9db033bed4f","2026-07-04","morning","ThreatNoir Weekend Brief — July 4","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-04\u002Fthreatnoir-morning-brief-2026-07-04.mp3"]