Two beta npm packages in the @joyfill namespace were compromised to deliver a DEV#POPPER-associated remote access trojan using import-time JavaScript implants and blockchain-based payload retrieval. The activity is linked to the same North Korean operation behind ViteVenom and also involved a Python infostealer tied to OmniStealer. #joyfill #DEVPOPPER #PolinRider #ContagiousInterview #ViteVenom #OmniStealer
Keypoints
- Two @joyfill beta npm packages were compromised with malicious code.
- The implant runs when Node.js loads the CommonJS entry point.
- Payloads are retrieved through Tron, Aptos, and BNB Smart Chain transactions.
- The final RAT can upload files, read clipboard data, and execute commands.
- A detached branch also delivers a Python infostealer linked to OmniStealer.
Read More: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html