Thecyberexpress Malicious Joyfill npm Packages Distribute DEV#POPPER RAT and Credential Stealer
Article Content
- •Two compromised Joyfill npm packages deliver DEV#POPPER RAT upon import.
- •Malware uses blockchain transactions for payload delivery, enhancing evasion tactics.
- •Developers are urged to audit their dependencies due to the potential for arbitrary code execution.
On July 28, 2026, two beta releases of Joyfill npm packages, @joyfill/layouts and @joyfill/components, were found to deliver the DEV#POPPER remote access trojan (RAT) and a credential stealer. The malware executes upon importing the compromised packages, bypassing traditional npm security measures. The affected packages collectively receive around 16,000 weekly downloads, with significant implications for developers using these dependencies. The malware employs a blockchain-based delivery method, allowing attackers to update payloads without new npm releases. It can execute arbitrary code, collect host information, and maintain persistence by modifying developer files. Security researchers have linked the malicious code to the PolinRider loader family and noted similarities to a previous incident involving DEV#POPPER. Developers are advised to review their dependencies and monitor for unusual activity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Dev#popper and Joyfill in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Supply Chain Attack Compromises Popular Rust Crates to Deliver Malware On August 20, 2026, a supply chain attack targeted the Rust ecosystem, compromising the widely used crates arrayref, append-only-vec, and internment. The attackers injected a malicious dependency, proc-macro1, which impersonated the legitimate proc-macro2 crate. During compilation, the build script executed…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…