LWA-2026-6018 MAL-2026-6826 ↗ confirmed malware

rollup-plugin-polyfill-handler@1.0.0

Malicious code in rollup-plugin-polyfill-handler (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

Package rollup-plugin-polyfill-handler is a combosquat that exports three functions (getPlugin, setPlugin, getPluginExten) which each make HTTP requests to rest-icon-handler[.]store, parse the response as JSON, and execute the result via eval(). This allows any code that calls these functions to download and run arbitrary payloads from a remote server. The README only documents a benign icon-fetching function (setDefaultModule), hiding the malicious downloader functions. The C2 host is rest-icon-handler[.]store.

analyzed by
Leitwacht
first seen
Jun 26, 2026, 03:34 PM
analyzed
Jun 26, 2026, 03:36 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.