{ads}

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js



July 29, 2026 at 09:50AM

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages "contain an import-time JavaScript implant that resolves encrypted code

from The Hacker News https://ift.tt/U1o0Jb5

0 Response to "Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js"

Post a Comment

Article Top Ads

Central Ads Article 1

Middle Ads Article 2

Article Bottom Ads