Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.

The list of affected packages is as follows –

@joyfill/layouts@0.1.2-2773.beta.0
@joyfill/components@4.0.0-rc24-2773-beta.4

The two packages “contain an import-time JavaScript implant that resolves encrypted code

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering

DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use

Write code like a human will maintain it

Write code like a human will maintain it Source: Hacker News

Blogger defeats photographer’s copyright claim

Blogger defeats photographer’s copyright claim Source: Hacker News