HackerFeeds

CyberSecurity News

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

The Hacker News
· July 29, 2026

AI summary

Two npm packages in the @joyfill namespace have been compromised, delivering a remote access trojan when imported into Node.js. The affected packages are beta release versions of @joyfill/layouts and @joyfill/components. These packages contain an import-time JavaScript implant that resolves encrypted code. The trojan is associated with the DEV#POPPER malware family. The compromised packages are @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4.

Read the full article at The Hacker Newsthehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.