Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
ID: c36a1f2a-8500-5cd0-9e40-feeb2ba6c06a
STIX ID: report--c36a1f2a-8500-5cd0-9e40-feeb2ba6c06a
Feed Name: Socket Blog
Two beta npm packages in the @joyfill namespace were published with an import-time JavaScript implant that uses blockchain-resident pointers (Tron/Aptos -> BSC) to fetch and decrypt further stages; one branch yields a 77 KB Node.js RAT with Socket.IO C2 and persistence in developer tools, and a detached branch fetches boot payloads (/$/boot) that can deploy an 82 KB Python credential stealer. Affected packages are @joyfill/[email protected] and @joyfill/[email protected]; indicators include multiple SHA-256 hashes, blockchain addresses/txids, C2 IPs, and the Sec-V marker; the report recommends isolating hosts, preserving artifacts, rotating credentials, and blocking the malicious package versions and related outbound blockchain RPC/C2 traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
