logo

Two Joyfill npm Packages Found Delivering DEV#POPPER Malware

ID: a3af40e2-ff6d-578a-856e-593bc2fc114f

STIX ID: report--a3af40e2-ff6d-578a-856e-593bc2fc114f

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-07-29

Date Updated: 2026-07-29

Author: Ashish Khaitan

...
...

Researchers identified two compromised joyfill npm beta packages that execute at import time to install a DEV#POPPER Node.js RAT capable of remote control, command execution, file exfiltration, and persistence; the loader fetches encrypted payloads via Tron, Aptos, and BNB Smart Chain transactions enabling dynamic updates, and additional payloads included a Python credential stealer. The packages were published 28 July 2026, affect developer/CI/production environments, and researchers recommend removing the affected releases, isolating impacted systems, rotating credentials, and monitoring for unusual blockchain RPC activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.