rollup-packages-polyfill-core@0.5.0
Malicious code in rollup-packages-polyfill-core (npm)
Analysis
rollup-packages-polyfill-core@0.5.0 combosquats the legitimate rollup-plugin-node-polyfills package. When the exported getPlugin() function is called, it decodes a base64-obfuscated command and silently runs "npm install glyphr --no-save --silent --no-audit --no-fund" via child_process.spawn with stdio suppressed and the process window hidden on Windows. After installation, it loads the glyphr module and invokes its plugin function. This pattern delivers a second-stage payload (the attacker-controlled glyphr package) from the npm registry under stealth conditions, making it a trojanized dependency downloader.
- analyzed by
- Leitwacht
- first seen
- Jun 13, 2026, 07:22 AM
- analyzed
- Jun 13, 2026, 11:39 AM
- weekly installs
- 97
Related advisories
- opentelemetry-plugin-graphql-example@55.33.111
- opentelemetry-contrib-scripts@55.33.111
- mongodb-example@55.33.111
- vps-adapter-core@1.0.0
- web3-core-utils@4.3.5
- prettier-lint-lenz@2.6.4
- vite-react-toolkit@1.0.1
- obfus-jsxy@3.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.