rollup-plugin-polyfill-build

MAL-2026-1967

npmmalware3/20/2026
Description

Malicious code in rollup-plugin-polyfill-build (npm)

Indicators of Compromise
SHA256 Hashes (2)
247aa97eb5ee832d4c9b9dd504fabc0fa12c4691995efd94b5c7c1d7931be038
66951e7a327d1fc859d6225c197895d0366cbe1dcb33f3fcf4879b223211a76a
Details
Ecosystemnpm
Attack Typemalware
Published3/20/2026
Affected Versions
0
Aliases
GHSA-49jr-xf59-c296
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001