step-security · Crawled Jul 28, 2026
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
16 IoCs
Read original article ↗
AI Summary
On July 28, 2026, malicious beta versions of the npm packages @joyfill/components and @joyfill/layouts were found to contain an obfuscated Remote Access Trojan (RAT) and credential stealer. The malware executes upon import, not install, enabling it to bypass traditional safeguards. It uses blockchain transactions to resolve command and control (C2) servers, establishes a Socket.IO-based remote access channel, and deploys a Python-based credential stealer targeting developer workstations. The packages were legitimate projects that were hijacked, and the malicious code was injected only into the published tarballs.
AI-extracted · verify before operational use
Indicators of Compromise 16 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 166[.]88[.]134[.]62 | Details → |
| IP | 23[.]27[.]13[.]43 | Details → |
| IP | 198[.]105[.]127[.]210 | Details → |
| IP | 23[.]27[.]202[.]27 | Details → |
| Domain | api[.]trongrid[.]io | Details → |
| Domain | fullnode[.]mainnet[.]aptoslabs[.]com | Details → |
| Domain | bsc-dataseed[.]binance[.]org | Details → |
| Domain | bsc-rpc[.]publicnode[.]com | Details → |
| Domain | ip-api[.]com | Details → |
| SHA-256 | 26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18 | Details → |
| SHA-256 | 36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c | Details → |
| Filename | dist/index.js | Details → |
| Filename | dist/index.esm.js | Details → |
| Filename | dist/joyfill.min.js | Details → |
| Filename | dist/index.cjs.js | Details → |
| Filename | dist/index.es.js | Details → |