Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Two npm packages in the @joyfill namespace have been compromised in their beta release versions to deliver a remote access trojan (RAT) linked to the DEV#POPPER malware family. The affected packages are @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4. According to the source, these packages "contain an import-time JavaScript implant that resolves encrypted code." The compromise was reported by The Hacker News on July 29, 2026. No further details about the attack vector, scope of impact, or remediation steps are provided in the source text.
// why it matters
Developers importing these packages risk executing a RAT on their systems.