
The affected releases are @joyfill/[email protected] and @joyfill/[email protected]. Joyfill develops software development kits for embedding forms, documents, and PDFs into web and mobile applications.
While both packages collectively receive around 16,000 weekly npm downloads, researchers noted that the figure overlaps because @joyfill/components depends on @joyfill/layouts, and it does not represent installations of the compromised beta versions.
Joyfill npm Packages Deliver DEV#POPPER RAT Malware
Unlike conventional npm attacks that rely on lifecycle scripts, the code patterns matching the PolinRider loader family and linked the , establish a Socket.IO remote-control channel, execute JavaScript or shell commands, upload files, access clipboard uses a multi-stage delivery process, retrieving encrypted payloads through Tron, Aptos and BNB Smart Chain transactions. believed, with medium confidence, to be a variant of OmniStealer.
Recommendations for Developers and Security Teams
The report also noted significant similarities to an incident analysed by eSentire earlier in 2026, in which DEV#POPPER was deployed via a weaponised GitHub repository. However, researchers believe the current campaign most likely resulted from a maintainer compromise rather than a malicious project clone.
that may remain even after the packages are removed.
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf thecyberexpress.com.
SOCIAL SHARE CARD GENERATOR