North Korean hackers exploit npm to target open source developers

JFrog's discovery of North Korean-backed packages masquerading as Rollup polyfills shows state-sponsored attackers shifting tactics: instead of targeting corporate networks directly, they're poisoning the software supply chain by compromising tools developers trust. The attack exploits an imbalance in open source security—package maintainers lack resources for rigorous vetting while millions of downstream projects automatically inherit compromised code, turning a single malicious upload into a breach vector across entire development ecosystems. By impersonating legitimate build tools, state actors signal they now view developer infrastructure as a higher-value target than endpoint security, since compromised build systems can harvest secrets and inject backdoors at scale.