BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Joyfill npm beta releases drop blockchain-linked RAT

Hackers used blockchain-based commands to hide a remote access trojan in npm packages.

  • Two beta npm packages from @joyfill were compromised to deliver the DEV#POPPER remote access trojan, using a multi-blockchain resolver structure.
  • The malware retrieves encrypted commands via Tron, Aptos, and BNB Smart Chain transactions, offering operational resilience and payload switching without new package versions.
  • The attack is linked to the North Korean threat cluster PolinRider, which also targeted the Vite ecosystem with similar blockchain-based command-and-control.

Security researchers have uncovered two compromised beta npm packages—@joyfill/layouts and @joyfill/components—that deliver a remote access trojan from the DEV#POPPER malware family. The packages contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions, according to an analysis by Socket.

- Advertisement -

Unlike typical malicious packages that trigger via npm lifecycle hooks, this implant runs automatically when Node.js loads the CommonJS entry point. Consequently, the use of a multi-blockchain resolver structure has been linked to the PolinRider threat cluster, which is assessed to be related to the Contagious Interview campaign.

The implant executes two parallel sequences: an in-process branch that retrieves a 77 KB JavaScript payload similar to DEV#POPPER, and a secondary branch that launches a detached Node.js process to fetch a separate boot payload. If the initial blockchain query to a Tron address fails, the malware falls back to an Aptos account to obtain a BSC transaction, then decrypts and executes the JavaScript code.

The final payload, “clientCode,” is a heavily obfuscated Node.js RAT capable of uploading files, reading clipboard data, and collecting host information. It also avoids execution on machines with hostnames like github-runner or buildbot. Meanwhile, the detached process delivers both the clientCode RAT and a Python infostealer—an iteration of OmniStealer—that harvests credentials, browser data, and developer tool configurations.

Socket told The Hacker News that both the ViteVenom campaign and these latest npm packages are part of the same ongoing operation by North Korean threat actors. Developers who installed the affected versions should remove them from lockfiles, caches, and build artifacts, and rotate any credentials exposed to the compromised Node.js process.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Polish court detains fifth suspect in Zondacrypto fraud case

A Polish court approved pretrial detention for Roman Ż., charged with computer fraud and...

Bitcoin-Gold Correlation Hits 6-Year High as Hedge Demand Rises

Bitcoin's correlation with Gold hits a six-year high, signaling its use as a hedge...

Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Cronos confirmed $9.19 million left its blockchain before a network rollback reversed a crypto...

Presearch Shut Down and Left Me With 60 Cents. Their Own Filings Show Why.

I bought €100 of PRE about two and a half years ago. I was...

Nvidia CEO touts GPUs as revenue-generating assets

NVIDIA CEO Jensen Huang says the company's GPUs are a “productive, revenue-generating asset” as...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading