Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Keypoints

  • Two @joyfill beta npm packages were compromised with malicious code.
  • The implant runs when Node.js loads the CommonJS entry point.
  • Payloads are retrieved through Tron, Aptos, and BNB Smart Chain transactions.
  • The final RAT can upload files, read clipboard data, and execute commands.
  • A detached branch also delivers a Python infostealer linked to OmniStealer.

Read More: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html