Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.

The list of affected packages is as follows –

@joyfill/layouts@0.1.2-2773.beta.0
@joyfill/components@4.0.0-rc24-2773-beta.4

The two packages “contain an import-time JavaScript implant that resolves encrypted code

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,

Attack Update: Top 5 Attack-IPs auf doode.info – 23.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 34.26.148.248 — 422 requests (recent log) 89.167.35.212 — 403 requests (recent log) 213.209.159.154 — 170 requests (recent

Attack Update: Top 5 Attack-IPs auf doode.info – 18.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 74.7.242.28 — 672 requests (recent log) 89.167.35.212 — 419 requests (recent log) 213.209.159.175 — 333 requests (recent