North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
A recent discovery has shed light on an insidious threat targeting web developers, with North Korea-linked actors exploiting popular JavaScript libraries to steal sensitive information. The malicious activity involves manipulating npm packages, which are used by millions of developers worldwide, to mimic legitimate Rollup polyfills and siphon off vital secrets. The attackers have been using … Read more