Fake Rollup Helper Packages on npm Traced to North Korean Hackers
Two look-alike JavaScript packages copied a popular developer tool line-for-line, then quietly opened a back door onto the machines of anyone who installed them.

Key points
- JFrog researchers found two malicious npm packages, "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core", posing as the legitimate rollup-plugin-polyfill-node project.
- The packages install remote-access code and steal developer secrets from any machine that runs them.
- JFrog attributes the campaign to hackers linked to North Korea, continuing a long-running push against software developers.
- Developers who installed either package should assume their credentials, tokens and wallet files are exposed.
Two fake developer tools slipped onto npm, the public library where JavaScript programmers download free code, and have been traced to hackers working for North Korea.
Security firm JFrog says the packages, named "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core", were built to impersonate a well-known helper called rollup-plugin-polyfill-node. That real package helps programmers make their code work across different runtime environments. The fakes copied its description and repository metadata precisely, so a busy developer skimming search results would struggle to spot the difference.
What did the fake packages actually do?
They opened a back door on the developer's computer and hunted for anything valuable. JFrog found the code sets up remote access, a hidden channel the attackers can use to run commands on the victim's machine, and then sweeps the system for secrets: saved passwords, cloud login credentials, source code and cryptocurrency wallet files.
A stolen cloud key can let an attacker log into a company's servers. A stolen wallet file can drain someone's crypto savings in minutes.
Why target developers at all?
Developers sit close to the money and close to the code. North Korea-linked crews, tracked under names like Lazarus and its sub-group sometimes called "Contagious Interview", have spent years hammering software engineers with fake job offers, poisoned open-source packages and fabricated coding tests. The goal is either straight cryptocurrency theft or a foothold inside a technology company for a bigger heist later.
The tactic is called a typosquat: attackers register a package name almost identical to a real one and wait for a typing mistake. It's cheap, quiet, and effective. We covered the same playbook on 23 June when three PostCSS-impersonating packages dropped a Windows remote-access trojan before researchers pulled them. On 26 June we also reported that North Korean malware was embedding prompts to mislead AI-assisted security tools, a sign the operators are actively countering modern defenses.
JFrog reported both packages to npm, which is owned by GitHub, and they've since been removed.
What should developers do now?
If you or your team installed either package, treat the machine as compromised. That's not a drill.
A sensible clean-up looks like this:
- Rotate every credential the machine touched: cloud provider keys, npm tokens, GitHub personal access tokens and SSH keys.
- Move cryptocurrency out of any wallet whose files sat on that device, using a clean computer.
- Rebuild the affected machine from a known-good image rather than trying to clean it.
- Check your package.json and lockfiles across every project for the two malicious names, and audit recent installs for other unfamiliar dependencies.
On the regulatory side, jurisdiction follows the victims. In the US, the FTC would take an interest, and the SEC would want to know if a listed company lost material data. The UK's ICO covers any personal data caught in the theft. Australia's OAIC notifiable data breach scheme applies once individuals are affected.
The npm ecosystem runs on trust, and North Korean operators have learned to hide inside that trust very well. Reading the package name twice before you hit install isn't paranoid anymore. It's the job.



