Discussion

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Started by The Hacker News · 29 Jul 2026 07:25 · 1 Views · 0 Replies
Thread Starter #0
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.

The list of affected packages is as follows -

@joyfill/[email protected]
@joyfill/[email protected]

The two packages "contain an import-time JavaScript implant that resolves encrypted code

Okumaya devam et...

You must be logged in to reply.

0 quotes selected