rollup-plugins-check@0.0.1
Malicious code in rollup-plugins-check (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall script (dist/module.js) makes an HTTPS GET request to workconfig[.]vercel[.]app (with TLS verification disabled) and passes the response body into new Function('require', data)(require), executing arbitrary remote code on the installer's machine with full Node.js require() access. The package claims to be a rollup polyfill plugin and references the legitimate FredKSchott/rollup-plugin-polyfill-node repository, but ships a malicious install-time downloader instead. IOC: workconfig[.]vercel[.]app (HTTPS).
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 05:29 AM
- analyzed
- Jul 30, 2026, 05:30 AM
Related advisories
- multi-acct@1.0.0
- merchantweb-lang-cookie-reset@0.0.6
- rollup-plugins-polyfills-rode@0.13.4
- test-flow-entire5@1.0.0
- express-middle@5.5.1
- test-flow-entire2@1.0.0
- test-flow-entire@1.0.0
- testingnewflow@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.