> Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
[DATE: 29/07/2026 04:20]
[LANGUAGE: EN]
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.
The list of affected packages is as follows -
@joyfill/[email protected]
@joyfill/[email protected]
The two packages "contain an import-time JavaScript implant that resolves encrypted code