Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Two compromised npm packages in the @joyfill namespace have been found to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family when imported into Node.js. The affected packages are @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.…
Intelligence analysis by Llama

Two compromised npm packages in the @joyfill namespace have been found to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family when imported into Node.js. The affected packages are @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4. The implant delivered as part of the JavaScript libraries runs when Node.js loads the CommonJ…
Imagine you're building a house, and someone sneaks in and installs a backdoor in the walls. That's basically what's happening with these compromised npm packages. When you import them into your project, they can run malicious code and give the attacker access to your system. It's like a Trojan horse, and it's a big deal because it can happen to anyone who uses these packages.
Analysis
A $60B Vote of Confidence
The discovery of two compromised npm packages in the @joyfill namespace has sent shockwaves through the developer community. The affected packages, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been found to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family when imported into Node.js. This is a significant development, as it highlights the ongoing threat of compromised npm packages and the importance of developers being vigilant about the packages they use in their projects.
The implant delivered as part of the JavaScript libraries runs when Node.js loads the CommonJS package entry point. This is a critical vulnerability, as it allows the attacker to execute arbitrary code in the context of any process that loads the package. This includes development environments, CI runners, test tooling, server-side rendering, and builds.
The use of a multi-blockchain resolver structure has also been linked to a threat cluster tracked as PolinRider, which is assessed to be related to Contagious Interview. This is a concerning development, as it suggests that the attackers are using a sophisticated and resilient command-and-control infrastructure to deliver their malware.
The affected packages are part of the @joyfill namespace, which is a popular collection of JavaScript libraries for building web applications. The discovery of these compromised packages highlights the importance of developers being aware of the packages they use in their projects and taking steps to ensure their security.
Why Cursor?
The discovery of these compromised packages raises several questions about the security of the npm ecosystem. How did these packages become compromised? What measures can developers take to ensure the security of their projects? And what can be done to prevent similar attacks in the future?
The answers to these questions are complex and multifaceted. However, one thing is clear: the discovery of these compromised packages highlights the ongoing threat of compromised npm packages and the importance of developers being vigilant about the packages they use in their projects.
The Road Ahead
The discovery of these compromised packages is a wake-up call for the developer community. It highlights the importance of being aware of the packages we use in our projects and taking steps to ensure their security. It also raises questions about the security of the npm ecosystem and what can be done to prevent similar attacks in the future.
In the short term, developers should take steps to ensure the security of their projects. This includes removing the affected packages from lockfiles, caches, internal mirrors, build images, and deployment artifacts, and rotating credentials from the affected Node.js process. In the long term, the npm ecosystem needs to take steps to improve its security and prevent similar attacks in the future.
Key points
- Two compromised npm packages in the @joyfill namespace have been found to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family when imported into Node.js.
- The affected packages are @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4.
- The implant delivered as part of the JavaScript libraries runs when Node.js loads the CommonJS package entry point.
- The use of a multi-blockchain resolver structure has been linked to a threat cluster tracked as PolinRider, which is assessed to be related to Contagious Interview.
The discovery of these compromised packages highlights the importance of developers being vigilant about the packages they use in their projects. In the short term, developers can take steps to ensure the security of their projects by removing the affected packages and rotating credentials. In the long term, the npm ecosystem needs to take steps to improve its security and prevent similar attacks in the future.
The use of a multi-blockchain resolver structure has been linked to a threat cluster tracked as PolinRider, which is assessed to be related to Contagious Interview. This is a concerning development, as it suggests that the attackers are using a sophisticated and resilient command-and-control infrastructure to deliver their malware.


