BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Joyfill npm beta releases drop blockchain-linked RAT

Hackers used blockchain-based commands to hide a remote access trojan in npm packages.

  • Two beta npm packages from @joyfill were compromised to deliver the DEV#POPPER remote access trojan, using a multi-blockchain resolver structure.
  • The malware retrieves encrypted commands via Tron, Aptos, and BNB Smart Chain transactions, offering operational resilience and payload switching without new package versions.
  • The attack is linked to the North Korean threat cluster PolinRider, which also targeted the Vite ecosystem with similar blockchain-based command-and-control.

Security researchers have uncovered two compromised beta npm packages—@joyfill/layouts and @joyfill/components—that deliver a remote access trojan from the DEV#POPPER malware family. The packages contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions, according to an analysis by Socket.

- Advertisement -

Unlike typical malicious packages that trigger via npm lifecycle hooks, this implant runs automatically when Node.js loads the CommonJS entry point. Consequently, the use of a multi-blockchain resolver structure has been linked to the PolinRider threat cluster, which is assessed to be related to the Contagious Interview campaign.

The implant executes two parallel sequences: an in-process branch that retrieves a 77 KB JavaScript payload similar to DEV#POPPER, and a secondary branch that launches a detached Node.js process to fetch a separate boot payload. If the initial blockchain query to a Tron address fails, the malware falls back to an Aptos account to obtain a BSC transaction, then decrypts and executes the JavaScript code.

The final payload, “clientCode,” is a heavily obfuscated Node.js RAT capable of uploading files, reading clipboard data, and collecting host information. It also avoids execution on machines with hostnames like github-runner or buildbot. Meanwhile, the detached process delivers both the clientCode RAT and a Python infostealer—an iteration of OmniStealer—that harvests credentials, browser data, and developer tool configurations.

Socket told The Hacker News that both the ViteVenom campaign and these latest npm packages are part of the same ongoing operation by North Korean threat actors. Developers who installed the affected versions should remove them from lockfiles, caches, and build artifacts, and rotate any credentials exposed to the compromised Node.js process.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Jane Street Boosts Bitcoin, XRP ETF Holdings in Q2 Filing

Jane Street more than doubled its Bitcoin ETF holdings in Q2 to roughly $1.01...

Upbit, Bithumb revenues plummet; Polymarket banned

Upbit parent company Dunamu reported a 49% drop in first-half operating revenue to $289...

MoonPay integrates Cash App Pay for crypto purchases

MoonPay has integrated Cash App Pay as a new payment option for US users...

StubMaker: 16 typosquat RubyGems packages steal data

Cybersecurity researchers have discovered a new typosquatting campaign, tracked as StubMaker, targeting RubyGems users...

Gold Slips 0.4% to $4,397 on Rising Yields, Oil

Gold prices fell 0.4% today, August 18, 2026, amid rising US Treasury yields and...

Must Read

Top 10 BEST Crypto Trading Books for New Traders

If you're thinking of diving into the crypto trading space, acquiring solid knowledge isn't just recommended - it's essential to protect your investment.Learning...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading