Dev#popper is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
Dev#popper is a malware family tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed July 3, 2026; most recent activity July 29, 2026.
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
On July 28, 2026, two beta releases of Joyfill npm packages, @joyfill/layouts and @joyfill/components, were found to deliver the DEV#POPPER remote access trojan (RAT) and a credential stealer. The malware executes upon…
Dev#popper is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
The most recent intelligence report mentioning Dev#popper on ThreatCluster is dated July 29, 2026. Activity was first observed July 3, 2026, giving a tracked span from then to July 29, 2026.
Across ThreatCluster reporting, Dev#popper most frequently co-occurs with Malware, Supply Chain Attack, PolinRider, CVE-2026-45504, OmniStealer, among 12 tracked related entities.
The most significant recent cluster is “Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages” (699 articles · Updated April 29, 2026). Dev#popper appears across 2 threat clusters in total, listed above with sources.
Dev#popper appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.