logo

Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

ID: c36a1f2a-8500-5cd0-9e40-feeb2ba6c06a

STIX ID: report--c36a1f2a-8500-5cd0-9e40-feeb2ba6c06a

Feed Name: Socket Blog

Threat Score
85/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: Socket Research Team

...
...

Two beta npm packages in the @joyfill namespace were published with an import-time JavaScript implant that uses blockchain-resident pointers (Tron/Aptos -> BSC) to fetch and decrypt further stages; one branch yields a 77 KB Node.js RAT with Socket.IO C2 and persistence in developer tools, and a detached branch fetches boot payloads (/$/boot) that can deploy an 82 KB Python credential stealer. Affected packages are @joyfill/[email protected] and @joyfill/[email protected]; indicators include multiple SHA-256 hashes, blockchain addresses/txids, C2 IPs, and the Sec-V marker; the report recommends isolating hosts, preserving artifacts, rotating credentials, and blocking the malicious package versions and related outbound blockchain RPC/C2 traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.