Fake npm Packages Target Rollup Polyfills to Steal Developer Secrets
Malicious npm packages linked to North Korean threat actors impersonate Rollup polyfills to steal sensitive data from developers. The packages, once installed, exfiltrate secrets like credentials and API keys. This supply chain attack underscores the ongoing risk of typosquatting and dependency confusion in open-source ecosystems.