ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Open Source

Compromised @joyfill npm beta packages embed RAT code on import

Source headline: Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 3 hours ago

Intelligence Summary

Two beta versions of npm packages under the @joyfill namespace were found to contain malicious code. Importing these packages in Node.js triggers an implant that decrypts and runs embedded functionality. The payload is tied to the DEV#POPPER malware family and is capable of establishing remote access. Affected releases include @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4. Developers should avoid the impacted versions, review dependency trees, and upgrade to trusted releases if available.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#supply-chain #malware #npm #rat #nodejs #dependency-security
Original reporting The Hacker News Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Open original source