2w ago · static-urls
The @joyfill npm scope was compromised on July 28, 2026, with two malicious beta packages (@joyfill/[email protected] and @joyfill/[email protected]) that delivered a blockchain-based command-and-control (C2) loader. The attack uses a two-stage supply chain compromise where the malicious code is embedded in production JavaScript bundles, executing upon import. The payload leverages public blockchain transactions (Tron and BSC) to fetch XOR-encrypted payloads, ultimately deploying a RAT client matching the PolinRider bot. This campaign shares infrastructure with the earlier astro.config.mjs attack, indicating a persistent threat actor using blockchain dead drops to evade detection.