hacker-news · Crawled Jul 29, 2026
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
3 IoCs
Read original article ↗
AI Summary
Two compromised npm packages in the @joyfill namespace, @joyfill/layouts and @joyfill/components, have been weaponized to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The malicious code executes at import time and uses a multi-blockchain resolver (Tron, Aptos, BNB Smart Chain) to retrieve and decrypt payloads, enabling resilient command-and-control. A secondary payload is fetched from a hardcoded IP address, leading to credential theft, reverse shell access, and persistence mechanisms. The activity is linked to North Korean threat actors and shares infrastructure with the ViteVenom campaign.
AI-extracted · verify before operational use
Indicators of Compromise 3 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 23[.]27[.]13[.]43 | Details → |
| Package | @joyfill/[email protected] | Details → |
| Package | @joyfill/[email protected] | Details → |