Joyfill npm Supply
A supply-chain compromise targeting the npm ecosystem has introduced a multi-stage remote access trojan (RAT) and credential stealer through hijacked Joyfill packages, highlighting an increasingly sophisticated abuse of trusted developer dependencies. On July 28, 2026, malicious beta releases of @joyfill/components and @joyfill/layouts were published to the npm registry, embedding heavily obfuscated payloads directly into compiled […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
