July 3, 2026

North Korea-linked npm packages impersonate Rollup polyfill tools to steal developer secrets

a blurry photo of a man and a woman walking in an office
Carrie Allen www.carrieallen.com / Unsplash

Security researchers at JFrog have identified a set of malicious npm packages linked to North Korean threat actors that impersonate legitimate Rollup polyfill tooling to steal developer credentials and enable remote access to compromised machines. Th...