hacker-news · Crawled Jul 29, 2026

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

3 IoCs
Read original article ↗

AI Summary

Two compromised npm packages in the @joyfill namespace, @joyfill/layouts and @joyfill/components, have been weaponized to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The malicious code executes at import time and uses a multi-blockchain resolver (Tron, Aptos, BNB Smart Chain) to retrieve and decrypt payloads, enabling resilient command-and-control. A secondary payload is fetched from a hardcoded IP address, leading to credential theft, reverse shell access, and persistence mechanisms. The activity is linked to North Korean threat actors and shares infrastructure with the ViteVenom campaign.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 23[.]27[.]13[.]43 Details →
Package @joyfill/[email protected] Details →
Package @joyfill/[email protected] Details →