Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.

The list of affected packages is as follows –

@joyfill/[email protected]
@joyfill/[email protected]

The two packages “contain an import-time JavaScript implant that resolves encrypted code

Leave a Reply

Your email address will not be published. Required fields are marked *