Skip to content
The Nexus
SECURITYJul 29 · 04:20 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Beta versions of two @joyfill npm packages have been compromised to deliver a remote access trojan (RAT) linked to the DEV#POPPER malware family. The affected packages are @joyfill/[email protected] and @joyfill/[email protected], which include an import-time JavaScript implant resolving encrypted code.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting