The Hacker NewsThursday · July 30, 2026FREE

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

npmsupply-chainmalwarejoyfill

Two npm packages in the @joyfill namespace have been compromised in their beta release versions to deliver a remote access trojan (RAT) linked to the DEV#POPPER malware family. The affected packages are @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4. According to the source, these packages "contain an import-time JavaScript implant that resolves encrypted code." The compromise was reported by The Hacker News on July 29, 2026. No further details about the attack vector, scope of impact, or remediation steps are provided in the source text.

// why it matters

Developers importing these packages risk executing a RAT on their systems.

Sources

Primary · The Hacker News
▸ Read original at thehackernews.com

Like this? Get the next digest.