LWA-2026-7235 confirmed malware

rollup-plugins-polyfills-rode@0.13.4

Malicious code in rollup-plugins-polyfills-rode (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat of the legitimate rollup-plugin-polyfill-node package. The postinstall script (dist/module.js) makes an HTTPS GET request to api[.]avax-test[.]dev/ext/bc/rpc with certificate validation disabled, then passes the response body to new Function('require', data)(require), executing arbitrary remote code at install time. The rest of the package contains legitimate browser polyfill code; the malicious payload is confined to the postinstall hook.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 09:54 PM
analyzed
Jul 29, 2026, 09:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.