LWA-2026-7241 MAL-2026-12429 ↗ confirmed malware

rollup-plugins-check@0.0.1

Malicious code in rollup-plugins-check (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall script (dist/module.js) makes an HTTPS GET request to workconfig[.]vercel[.]app (with TLS verification disabled) and passes the response body into new Function('require', data)(require), executing arbitrary remote code on the installer's machine with full Node.js require() access. The package claims to be a rollup polyfill plugin and references the legitimate FredKSchott/rollup-plugin-polyfill-node repository, but ships a malicious install-time downloader instead. IOC: workconfig[.]vercel[.]app (HTTPS).

analyzed by
Leitwacht
first seen
Jul 30, 2026, 05:29 AM
analyzed
Jul 30, 2026, 05:30 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.