static-urls · Crawled Jul 31, 2026

Joyfill npm Packages Compromised with Blockchain C2 Loader - Real-time Open Source Software Supply Chain Security

12 IoCs
Read original article ↗

AI Summary

The @joyfill npm scope was compromised on July 28, 2026, with two malicious beta packages (@joyfill/[email protected] and @joyfill/[email protected]) that delivered a blockchain-based command-and-control (C2) loader. The attack uses a two-stage supply chain compromise where the malicious code is embedded in production JavaScript bundles, executing upon import. The payload leverages public blockchain transactions (Tron and BSC) to fetch XOR-encrypted payloads, ultimately deploying a RAT client matching the PolinRider bot. This campaign shares infrastructure with the earlier astro.config.mjs attack, indicating a persistent threat actor using blockchain dead drops to evade detection.

AI-extracted · verify before operational use

Indicators of Compromise 12 extracted

Type Value Detail
Package @joyfill/[email protected] Details →
SHA-256 adc4af90540d33cd1e98f44b51482ae9250fbeb97d6f8d7841c81b618cb2c6e6 Details →
SHA-256 bcc93dc55bc7daedf4ca57254f0e7a7f1c40e09851eab98fe10cde801982db17 Details →
Domain api[.]trongrid[.]io Details →
Domain bsc-dataseed[.]binance[.]org Details →
Domain bsc-rpc[.]publicnode[.]com Details →
Domain fullnode[.]mainnet[.]aptoslabs[.]com Details →
IP 166[.]88[.]134[.]62 Details →
IP 198[.]105[.]127[.]210 Details →
IP 23[.]27[.]202[.]27 Details →
Filename dist/index.cjs.js Details →
Filename dist/index.es.js Details →