Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Blog post from Socket
In two beta releases of npm packages under the @joyfill namespace, a JavaScript implant was discovered that uses blockchain transactions to resolve encrypted code, leading to a 77 KB Node.js remote-access trojan. The packages, @joyfill/layouts and @joyfill/components, are used for embedding forms and documents into applications, and the malicious code executes during the import process, bypassing npm install safeguards. The implant, linked to the PolinRider and DEV#POPPER malware families, enables remote control, data collection, and manipulation on infected systems, posing a significant security threat to development environments, CI runners, and other processes that load the affected modules. The compromised versions were published under the same npm identity and are characterized by distinctive multi-chain resolution structures and XOR keys. Security teams and developers are advised to isolate affected systems, remove compromised versions from their environments, and monitor for suspicious blockchain RPC traffic and network activities indicative of the implant's presence.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Vector Search | 1 | 1,957 | 402 | 133 | +3% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.