Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Two compromised npm packages within the @joyfill namespace have been injected with a remote access trojan (RAT) linked to the DEV#POPPER malware family. These packages utilize a complex blockchain-based infrastructure (Tron, Aptos, and BNB Smart Chain) to deliver a JavaScript payload that functions as a Node.js RAT, capable of collecting extensive host information, including credentials, browser data, and Git repositories. The packages are associated with the North Korean threat actor group PolinRider, and are a continuation of a larger operation involving the ViteVenom malware family. Developers are strongly advised to remove the affected packages and rotate credentials.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
