Researchers identified a malicious npm supply-chain campaign that impersonated Rollup polyfill tooling to compromise developer workstations and CI/build systems. The primary packages, rollup-packages-polyfill-core and rollup-runtime-polyfill-core, mimicked legitimate Rollup-related projects and used staged dependencies including swift-parse-stream, quirky-token, react-icon-svgs, and rollup-plugin-polyfill-connect to trigger a multi-stage infection chain. The malware fetched obfuscated code from JSONKeeper, decrypted additional payloads retrieved from 216.126.236.244, and executed them locally while using evasive checks to avoid some analysis and cloud development environments.
The final payloads gave attackers remote access and enabled theft of browser data, crypto-wallet information, files, clipboard contents, and other developer secrets such as source code, tokens, SSH keys, and cloud credentials. JFrog said the layered package structure, lookalike naming, and tradecraft resemble earlier Lazarus-linked npm operations, while additional reporting tied the activity to a broader North Korea-linked supply-chain effort referred to as PolinRider. Some malicious packages were replaced with security-holding versions, but others remained available at the time of reporting, prompting guidance to remove the packages, treat affected hosts as compromised, rotate credentials, and block related outbound traffic.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
A Bluesky post shared a Socket article about the PolinRider supply-chain campaign and described it as North Korea-linked. The post said the operation was expanding across open source ecosystems and associated it with OmniStealer and PolinRider.
At the time of JFrog's analysis, two of the malicious npm packages had been replaced with security-holding versions on npm, while four malicious packages remained available. This reflected a partial response to the campaign but not full removal of the threat.
JFrog identified a cluster of malicious npm packages, including rollup-packages-polyfill-core and rollup-runtime-polyfill-core, masquerading as Rollup polyfill tooling. The packages used a multi-stage infection chain to fetch obfuscated code and deploy payloads for remote access, data theft, filesystem collection, and clipboard monitoring.
Kudelski Security published research on a DPRK-linked 'Contagious Interview' campaign in which operators posing as recruiters tricked developers into running malicious code during fake technical interviews. The report documented a trojanized GitHub repository named Ajuna-solution, C2 infrastructure at 138.201.128.169:1224, remote command execution via eval(), and detection guidance including Suricata and YARA logic.
Checkmarx reported that at least eight malicious PyPI packages tied to Operation Navy Ghost were uploaded between November 2025 and June 2026. The packages masqueraded as legitimate Pyrogram forks and shared identical backdoor logic and operator identifiers.
A supply-chain campaign dubbed Operation Navy Ghost began targeting Python developers building Telegram bots by publishing trojanized Pyrogram forks on PyPI. The malicious packages were active since November 2025 and contained a hidden backdoor that enabled arbitrary code execution, file access, and data exfiltration via Telegram.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 223 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcebsky.app
Open sourcebleepingcomputer.com
Open sourceresearch.jfrog.com
Open sourcekudelskisecurity.com
Open sourceabout.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.