Malicious Joyfill npm Packages Distribute DEV#POPPER RAT and Credential Stealer

Malicious Joyfill npm Packages Distribute DEV#POPPER RAT and Credential Stealer

First seen 29 Jul 2026, 11:34 UTC ThehackernewsGbhackersThecyberexpressCybersecuritynewsget.adobe.com 84% similarity 69.0

Article Content

Browse articles
ThreatCluster

On July 28, 2026, two beta releases of Joyfill npm packages, @joyfill/layouts and @joyfill/components, were found to deliver the DEV#POPPER remote access trojan (RAT) and a credential stealer. The malware executes upon importing the compromised packages, bypassing traditional npm security measures. The affected packages collectively receive around 16,000 weekly downloads, with significant implications for developers using these dependencies. The malware employs a blockchain-based delivery method, allowing attackers to update payloads without new npm releases. It can execute arbitrary code, collect host information, and maintain persistence by modifying developer files. Security researchers have linked the malicious code to the PolinRider loader family and noted similarities to a previous incident involving DEV#POPPER. Developers are advised to review their dependencies and monitor for unusual activity.

Key Points: • Two compromised Joyfill npm packages deliver DEV#POPPER RAT upon import. • Malware uses blockchain transactions for payload delivery, enhancing evasion tactics. • Developers are urged to audit their dependencies due to the potential for arbitrary code execution.

ThreatCluster AI How this analysis works

Timeline

2026-07-28
Malicious Joyfill packages published
Beta releases of @joyfill/layouts and @joyfill/components were published, embedding RAT payloads.
Thecyberexpress
2026-07-28
Malware execution method identified
Malicious code executes during package import, bypassing npm install --ignore-scripts.
Gbhackers
2026-07-29
Security warnings issued
Researchers warn of the malware's capabilities, including arbitrary code execution and credential theft.
Thehackernews

Community

Browse all →