Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
2,331
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

In two beta releases of npm packages under the @joyfill namespace, a JavaScript implant was discovered that uses blockchain transactions to resolve encrypted code, leading to a 77 KB Node.js remote-access trojan. The packages, @joyfill/layouts and @joyfill/components, are used for embedding forms and documents into applications, and the malicious code executes during the import process, bypassing npm install safeguards. The implant, linked to the PolinRider and DEV#POPPER malware families, enables remote control, data collection, and manipulation on infected systems, posing a significant security threat to development environments, CI runners, and other processes that load the affected modules. The compromised versions were published under the same npm identity and are characterized by distinctive multi-chain resolution structures and XOR keys. Security teams and developers are advised to isolate affected systems, remove compromised versions from their environments, and monitor for suspicious blockchain RPC traffic and network activities indicative of the implant's presence.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Vector Search 1 1,957 402 133 +3%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.