< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-07-29T09:50:57+05:30

Compromised @joyfill npm Packages Execute RAT via Blockchain-Based C2 Infrastructure

Two compromised npm packages in the @joyfill namespace deliver a Remote Access Trojan (RAT) via blockchain-based command-and-control (C2) infrastructure, linked to the DEV#POPPER malware family and North Korean threat actors. The malicious code executes upon import into Node.js, enabling credential theft, file exfiltration, and remote control through Tron, Aptos, and BNB Smart Chain transactions.

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.

The list of affected packages is as follows -

@joyfill/[email protected] @joyfill/[email protected]

The two packages "contain an import-time JavaScript implant that resolves encrypted code

Read original article

*** END OF TRANSMISSION ***