static-urls · Crawled Jul 31, 2026
Joyfill npm Packages Compromised with Blockchain C2 Loader - Real-time Open Source Software Supply Chain Security
12 IoCs
Read original article ↗
AI Summary
The @joyfill npm scope was compromised on July 28, 2026, with two malicious beta packages (@joyfill/[email protected] and @joyfill/[email protected]) that delivered a blockchain-based command-and-control (C2) loader. The attack uses a two-stage supply chain compromise where the malicious code is embedded in production JavaScript bundles, executing upon import. The payload leverages public blockchain transactions (Tron and BSC) to fetch XOR-encrypted payloads, ultimately deploying a RAT client matching the PolinRider bot. This campaign shares infrastructure with the earlier astro.config.mjs attack, indicating a persistent threat actor using blockchain dead drops to evade detection.
AI-extracted · verify before operational use
Indicators of Compromise 12 extracted
| Type | Value | Detail |
|---|---|---|
| Package | @joyfill/[email protected] | Details → |
| SHA-256 | adc4af90540d33cd1e98f44b51482ae9250fbeb97d6f8d7841c81b618cb2c6e6 | Details → |
| SHA-256 | bcc93dc55bc7daedf4ca57254f0e7a7f1c40e09851eab98fe10cde801982db17 | Details → |
| Domain | api[.]trongrid[.]io | Details → |
| Domain | bsc-dataseed[.]binance[.]org | Details → |
| Domain | bsc-rpc[.]publicnode[.]com | Details → |
| Domain | fullnode[.]mainnet[.]aptoslabs[.]com | Details → |
| IP | 166[.]88[.]134[.]62 | Details → |
| IP | 198[.]105[.]127[.]210 | Details → |
| IP | 23[.]27[.]202[.]27 | Details → |
| Filename | dist/index.cjs.js | Details → |
| Filename | dist/index.es.js | Details → |