Skip to main content
CyberSingle-sourceMediumDeveloping
5.5

Compromised Joyfill npm packages execute malware via Node.js import

Two beta npm packages from the Joyfill library have been identified as containing malicious code that executes upon import, bypassing traditional install-hook detection. The malware utilizes a multi-blockchain retrieval mechanism to fetch a remote access trojan (RAT) linked to the DEV#POPPER threat actor, maintaining persistence beyond the initial build or test process.

The Hacker News2 days agoCredibility 52%View source

Score Breakdown

Mosaic Score5.5
Confidence0.9
Significance0.5
Source credibility0.5
Source

Related signals

8 found