ShellCodeX Intelligence Brief
HIGH
Open Source
Compromised @joyfill npm beta packages embed RAT code on import
Source headline: Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Threat level
High
Signal strength
75/100
Source confidence
1 source
Published
3 hours ago
Intelligence Summary
Two beta versions of npm packages under the @joyfill namespace were found to contain malicious code. Importing these packages in Node.js triggers an implant that decrypts and runs embedded functionality. The payload is tied to the DEV#POPPER malware family and is capable of establishing remote access. Affected releases include @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4. Developers should avoid the impacted versions, review dependency trees, and upgrade to trusted releases if available.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
The Hacker News
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Open original source