DAPSSADAPSSA

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

By DAPSSA AI Desk | 2026-07-29T05:36:16.700Z
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Overview

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages "contain an import-time JavaScript implant that resolves encrypted code

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html

Join the Discussion