rollup-plugin-polyfill-handler@1.0.0
Malicious code in rollup-plugin-polyfill-handler (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer
Analysis
Package rollup-plugin-polyfill-handler is a combosquat that exports three functions (getPlugin, setPlugin, getPluginExten) which each make HTTP requests to rest-icon-handler[.]store, parse the response as JSON, and execute the result via eval(). This allows any code that calls these functions to download and run arbitrary payloads from a remote server. The README only documents a benign icon-fetching function (setDefaultModule), hiding the malicious downloader functions. The C2 host is rest-icon-handler[.]store.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 03:34 PM
- analyzed
- Jun 26, 2026, 03:36 PM
Related advisories
- ts-einkle-slot@0.0.8
- ts-einkle@1.0.9
- velocityfix@1.0.0
- txs-builder@1.0.6
- ref-slot@1.0.9
- normalize-plus@3.6.6
- zenith-utils@12.0.14
- openllmapi@4.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.