
Joyfill npm Credential Stealer Targets GitHub Tokens, Browser Passwords and Crypto Wallets
Malicious beta releases of the legitimate Joyfill npm packages @joyfill/components and @joyfill/layouts were published on July 28, 2026, carrying an advanced credential-stealing remote access trojan (RAT). The attack is critical because the injected code runs when an application imports the affected package. This means npm install --ignore-scripts does not prevent execution. Developers, CI/CD environments, and […]
The post Joyfill npm Credential Stealer Targets GitHub Tokens, Browser Passwords and Crypto Wallets appeared first on Cyber Security News.