Malicious joyfill npm Packages Distribute DEV#POPPER RAT via Blockchain

Malicious joyfill npm Packages Distribute DEV#POPPER RAT via Blockchain

First seen 29 Jul 2026, 11:34 UTC ThehackernewsThecyberexpressget.adobe.com 82% similarity 69.5

Article Content

Browse articles
ThreatCluster

Two beta releases of joyfill npm packages were found delivering the DEV#POPPER remote access trojan (RAT). The compromised packages, @joyfill/[email protected] and @joyfill/[email protected], utilize an import-time loader to retrieve encrypted payloads through blockchain transactions. This attack method allows the malware to execute during package importation, bypassing traditional npm security measures. The malware can execute arbitrary code, establish remote control channels, and collect sensitive information. The malicious packages were published on July 28, 2026, and have around 16,000 weekly downloads, although the affected versions are not fully reflected in this number. Researchers have linked the malware to previous incidents but have not attributed it to a specific threat actor. The use of blockchain for payload delivery enables attackers to update the malware without releasing new npm versions.

Key Points: • Two joyfill npm packages were found distributing DEV#POPPER RAT malware. • Malware executes during import, bypassing traditional npm security measures. • Attackers can update payloads via blockchain transactions without new releases.

ThreatCluster AI How this analysis works

Timeline

2026-07-28
Malicious joyfill npm packages published
The compromised packages @joyfill/layouts and @joyfill/components were published, containing the DEV#POPPER RAT.
Thecyberexpress
2026-07-29
Security reports released
Security researchers confirmed the presence of DEV#POPPER malware in the joyfill npm packages.
Thehackernews

Community

Browse all →

Tracked Entities in This Story