Thecyberexpress
Malicious joyfill npm Packages Distribute DEV#POPPER RAT via Blockchain
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two beta releases of joyfill npm packages were found delivering the DEV#POPPER remote access trojan (RAT). The compromised packages, @joyfill/[email protected] and @joyfill/[email protected], utilize an import-time loader to retrieve encrypted payloads through blockchain transactions. This attack method allows the malware to execute during package importation, bypassing traditional npm security measures. The malware can execute arbitrary code, establish remote control channels, and collect sensitive information. The malicious packages were published on July 28, 2026, and have around 16,000 weekly downloads, although the affected versions are not fully reflected in this number. Researchers have linked the malware to previous incidents but have not attributed it to a specific threat actor. The use of blockchain for payload delivery enables attackers to update the malware without releasing new npm versions.
Key Points: • Two joyfill npm packages were found distributing DEV#POPPER RAT malware. • Malware executes during import, bypassing traditional npm security measures. • Attackers can update payloads via blockchain transactions without new releases.