As cited
Copy frozen at (site build).
threat intel
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Two beta versions of npm packages in the @joyfill namespace were compromised to distribute a remote access trojan tied to the DEV#POPPER malware family. The affected packages execute encrypted malicious code upon import into Node.js applications. The compromise demonstrates ongoing supply chain risks in public package repositories.
Why it matters: Developers using @joyfill/layouts@0.1.2-2773.beta.0 or @joyfill/components@4.0.0-rc24-2773-beta.4 need to audit their projects immediately and remove these versions to prevent RAT installation in their build environments and production systems.
- Source published
- First seen by Cybersecurity Tracker