
Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials
A fresh supply chain scare hit software teams after attackers slipped malware into trusted open source libraries. On July 28, 2026, malicious beta builds of two Joyfill packages appeared on the npm registry. The libraries, @joyfill/components and @joyfill/layouts, are used for forms and layout work in many web apps. Anyone who imported those beta builds […]
The post Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials appeared first on Cyber Security News.