Thecyberexpress
Malicious Joyfill npm Packages Distribute DEV#POPPER RAT and Credential Stealer
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 28, 2026, two beta releases of Joyfill npm packages, @joyfill/layouts and @joyfill/components, were found to deliver the DEV#POPPER remote access trojan (RAT) and a credential stealer. The malware executes upon importing the compromised packages, bypassing traditional npm security measures. The affected packages collectively receive around 16,000 weekly downloads, with significant implications for developers using these dependencies. The malware employs a blockchain-based delivery method, allowing attackers to update payloads without new npm releases. It can execute arbitrary code, collect host information, and maintain persistence by modifying developer files. Security researchers have linked the malicious code to the PolinRider loader family and noted similarities to a previous incident involving DEV#POPPER. Developers are advised to review their dependencies and monitor for unusual activity.
Key Points: • Two compromised Joyfill npm packages deliver DEV#POPPER RAT upon import. • Malware uses blockchain transactions for payload delivery, enhancing evasion tactics. • Developers are urged to audit their dependencies due to the potential for arbitrary code execution.