
Two Joyfill npm Packages Found Delivering DEV#POPPER Malware
Two beta releases of joyfill npm Packages have been found distributing a malware implant capable of delivering the DEV#POPPER remote access trojan (RAT) . The compromised Node.js packages use an import-time loader that retrieves encrypted payloads through blockchain transactions instead of traditional command-and-control infrastructure.
The affected releases are @joyfill/[email protected] and @joyfill/[email protected]. Joyfill develops software development kits for embedding forms, documents, and PDFs into web and mobile applications.
While both packages collectively receive around 16,000 weekly npm downloads, researchers noted that the figure overlaps becaus...