SECURITYTHE HACKER NEWS
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Beta versions of two @joyfill npm packages have been compromised to deliver a remote access trojan (RAT) linked to the DEV#POPPER malware family. The affected packages are @joyfill/[email protected] and @joyfill/[email protected], which include an import-time JavaScript implant resolving encrypted code.
Related Signal
Adjacent reporting
- Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
- Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
- Axios NPM Package Compromised in Precision Attack
- North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
- New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs