← volver al portal

Compromised Joyfill npm Packages Distribute Remote Access Trojan

Two beta versions of npm packages in the @joyfill namespace were compromised to deliver a remote access trojan (RAT) linked to the DEV#POPPER malware…

Immediately check if you use @joyfill/layouts or @joyfill/components in your Node.js projects. Uninstall the compromised beta versions listed, update to trusted stable releases, and scan your systems for DEV#POPPER RAT artifacts. Implement npm dependency verification and integrity checking in your CI/CD pipeline.