BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Joyfill npm beta releases drop blockchain-linked RAT

Hackers used blockchain-based commands to hide a remote access trojan in npm packages.

  • Two beta npm packages from @joyfill were compromised to deliver the DEV#POPPER remote access trojan, using a multi-blockchain resolver structure.
  • The malware retrieves encrypted commands via Tron, Aptos, and BNB Smart Chain transactions, offering operational resilience and payload switching without new package versions.
  • The attack is linked to the North Korean threat cluster PolinRider, which also targeted the Vite ecosystem with similar blockchain-based command-and-control.

Security researchers have uncovered two compromised beta npm packages—@joyfill/layouts and @joyfill/components—that deliver a remote access trojan from the DEV#POPPER malware family. The packages contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions, according to an analysis by Socket.

- Advertisement -

Unlike typical malicious packages that trigger via npm lifecycle hooks, this implant runs automatically when Node.js loads the CommonJS entry point. Consequently, the use of a multi-blockchain resolver structure has been linked to the PolinRider threat cluster, which is assessed to be related to the Contagious Interview campaign.

The implant executes two parallel sequences: an in-process branch that retrieves a 77 KB JavaScript payload similar to DEV#POPPER, and a secondary branch that launches a detached Node.js process to fetch a separate boot payload. If the initial blockchain query to a Tron address fails, the malware falls back to an Aptos account to obtain a BSC transaction, then decrypts and executes the JavaScript code.

The final payload, “clientCode,” is a heavily obfuscated Node.js RAT capable of uploading files, reading clipboard data, and collecting host information. It also avoids execution on machines with hostnames like github-runner or buildbot. Meanwhile, the detached process delivers both the clientCode RAT and a Python infostealer—an iteration of OmniStealer—that harvests credentials, browser data, and developer tool configurations.

Socket told The Hacker News that both the ViteVenom campaign and these latest npm packages are part of the same ongoing operation by North Korean threat actors. Developers who installed the affected versions should remove them from lockfiles, caches, and build artifacts, and rotate any credentials exposed to the compromised Node.js process.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin ETFs bleed $526M as BTC fails to hold $65K

US spot Bitcoin ETFs recorded four consecutive trading sessions of net outflows totaling approximately...

Tether Signs Tokenization Deal with Nairobi Exchange

Tether and the Nairobi Securities Exchange signed an MoU to explore tokenized securities and...

US-Iran Ceasefire Doubt Grows as Polymarket Odds Drop 10%

The United States announced a ceasefire with Iran yesterday, but prediction markets show skepticism...

Visa Q3 Profit Beats, Revenue Surges 14%

VISA posted fiscal Q3 net revenue of $11.6B, up 14% year-over-year and above analyst...

Core Scientific takes $41.9M loss to cancel Block chip deal

Core Scientific paid Block $67.9 million for Bitcoin mining chips, then booked a $41.9...

Must Read

Top 10 Best Blockchain Games

If you want to know about the best blockchain games then read this article carefully. We listed the best games you can play and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading