LWA-2026-7235 confirmed malware
rollup-plugins-polyfills-rode@0.13.4
Malicious code in rollup-plugins-polyfills-rode (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Combosquat of the legitimate rollup-plugin-polyfill-node package. The postinstall script (dist/module.js) makes an HTTPS GET request to api[.]avax-test[.]dev/ext/bc/rpc with certificate validation disabled, then passes the response body to new Function('require', data)(require), executing arbitrary remote code at install time. The rest of the package contains legitimate browser polyfill code; the malicious payload is confined to the postinstall hook.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 09:54 PM
- analyzed
- Jul 29, 2026, 09:55 PM
Related advisories
- test-flow-entire5@1.0.0
- express-middle@5.5.1
- test-flow-entire2@1.0.0
- test-flow-entire@1.0.0
- testingnewflow@1.0.0
- kyksworldcup4@1.0.0
- flat-logger-core@1.0.0
- streak-cal-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.