step-security · Crawled Jul 28, 2026

Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

16 IoCs
Read original article ↗

AI Summary

On July 28, 2026, malicious beta versions of the npm packages @joyfill/components and @joyfill/layouts were found to contain an obfuscated Remote Access Trojan (RAT) and credential stealer. The malware executes upon import, not install, enabling it to bypass traditional safeguards. It uses blockchain transactions to resolve command and control (C2) servers, establishes a Socket.IO-based remote access channel, and deploys a Python-based credential stealer targeting developer workstations. The packages were legitimate projects that were hijacked, and the malicious code was injected only into the published tarballs.

AI-extracted · verify before operational use

Indicators of Compromise 16 extracted

Type Value Detail
IP 166[.]88[.]134[.]62 Details →
IP 23[.]27[.]13[.]43 Details →
IP 198[.]105[.]127[.]210 Details →
IP 23[.]27[.]202[.]27 Details →
Domain api[.]trongrid[.]io Details →
Domain fullnode[.]mainnet[.]aptoslabs[.]com Details →
Domain bsc-dataseed[.]binance[.]org Details →
Domain bsc-rpc[.]publicnode[.]com Details →
Domain ip-api[.]com Details →
SHA-256 26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18 Details →
SHA-256 36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c Details →
Filename dist/index.js Details →
Filename dist/index.esm.js Details →
Filename dist/joyfill.min.js Details →
Filename dist/index.cjs.js Details →
Filename dist/index.es.js Details →