Compromised Joyfill npm Packages Distribute Remote Access Trojan
Two beta versions of npm packages in the @joyfill namespace were compromised to deliver a remote access trojan (RAT) linked to the DEV#POPPER malware…
Immediately check if you use @joyfill/layouts or @joyfill/components in your Node.js projects. Uninstall the compromised beta versions listed, update to trusted stable releases, and scan your systems for DEV#POPPER RAT artifacts. Implement npm dependency verification and integrity checking in your CI/CD pipeline.