🕵️ SicherheitslückenCVE-2026-58744 | Google Android input validation (EUVD-2026-79015)(15.09.2026 um 22:21 Uhr)
🕵️ SicherheitslückenCVE-2026-58744 | Google Android input validation (EUVD-2026-79015)(15.09.2026 um 22:21 Uhr)

📰 IT Security Nachrichten 🕛 vor 1 Monat 3 Min Lesezeit SECURITY-FEED
0

Two Joyfill npm Packages Found Delivering DEV#POPPER Malware

↗ Quelle (thecyberexpress.com)
🗣️ Stimme:
📑 Inhaltsübersicht

joyfill npm Packages

Two beta releases of joyfill npm Packages have been found distributing a malware implant capable of delivering the DEV#POPPER remote access trojan (RAT) . The compromised Node.js packages use an import-time loader that retrieves encrypted payloads through blockchain transactions instead of traditional command-and-control infrastructure. 

The affected releases are @joyfill/[email protected] and @joyfill/[email protected]. Joyfill develops software development kits for embedding forms, documents, and PDFs into web and mobile applications.

While both packages collectively receive around 16,000 weekly npm downloads, researchers noted that the figure overlaps because @joyfill/components depends on @joyfill/layouts, and it does not represent installations of the compromised beta versions. 

Joyfill npm Packages Deliver DEV#POPPER RAT Malware


Unlike conventional npm attacks that rely on lifecycle scripts, the  code patterns matching the PolinRider loader family and linked the , establish a Socket.IO remote-control channel, execute JavaScript or shell commands, upload files, access clipboard uses a multi-stage delivery process, retrieving encrypted payloads through Tron, Aptos and BNB Smart Chain transactions. believed, with medium confidence, to be a variant of OmniStealer. 

Recommendations for Developers and Security Teams 


The report also noted significant similarities to an incident analysed by eSentire earlier in 2026, in which DEV#POPPER was deployed via a weaponised GitHub repository. However, researchers believe the current campaign most likely resulted from a maintainer compromise rather than a malicious project clone. 

that may remain even after the packages are removed. 
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf thecyberexpress.com.
↗ Original-Artikel auf thecyberexpress.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
RoboGators, HBOMAX, Microsoft, DAS, Horsebot 3000, Aaran Leyland does AI, and More - SWN #616
1 Quelle
Trust at the Speed of Business: Why ISO 27001, SOC 2, TISAX, and CMMC are Growth Strategies, Not Compliance Projects
1 Quelle
U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog