Dossier
DEV#POPPER
Coverage of DEV#POPPER in the Nexus archive.
- Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Beta versions of two @joyfill npm packages have been compromised to deliver a remote access trojan (RAT) linked to the DEV#POPPER malware family. The affected packages are @joyfill/[email protected] and @joyfill/[email protected], which include an import-time JavaScript implant resolving encrypted code.