Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Compromised npm Packages Distribute RAT via Node.js

Compromised npm Packages Distribute RAT via Node.js

Posted on July 29, 2026 By CWS

Two npm packages in the @joyfill namespace have been discovered to contain remote access trojan (RAT) malware. These compromised beta versions aim to infect systems using the Node.js environment with malicious code linked to the DEV#POPPER malware family.

Affected Packages and Malware Delivery

The impacted packages include @joyfill/[email protected] and @joyfill/[email protected]. An analysis by Socket revealed that these packages employ a JavaScript implant activated during import, resolving encrypted code through transactions on the Tron, Aptos, and BNB Smart Chain blockchains.

This method differs from typical malicious packages, which usually activate via npm lifecycle hooks. Instead, the JavaScript implant executes as soon as the Node.js loads the CommonJS package entry point, indicating a sophisticated attack strategy.

Blockchain Utilization and Threat Analysis

The attack employs a multi-blockchain resolver structure, previously associated with a threat group known as PolinRider, and related to Contagious Interview. This approach enables operational flexibility, allowing payload changes without the need to update package versions.

Earlier reports by Checkmarx and OpenSourceMalware identified similar strategies in the ViteVenom campaign, targeting Vite frontend tooling with a tiered blockchain C2 infrastructure. This method delivers RATs capable of reverse shells, credential theft, and persistent backdoor injections.

Payload Execution and Developer Precautions

The malware initiates with a JavaScript loader that retrieves a secondary malware stage named “clientCode” through blockchain resolution. A separate Node.js process also engages a different IP address to execute additional code.

Developers using these packages should remove affected versions from their systems, including lockfiles, caches, and build images. It’s crucial to switch to a verified version and update credentials to mitigate risks.

Socket advises that the @joyfill/layouts package poses a threat of arbitrary code execution, affecting development environments, CI runners, and more. The ultimate payload can collect host data, establish remote connections, and execute various commands, posing significant security risks.

The incident highlights ongoing cybersecurity challenges, emphasizing the need for vigilance in package management and the importance of maintaining secure development practices.

The Hacker News Tags:Blockchain, Checkmarx, Contagious Interview, Cybersecurity, DEV#POPPER, JavaScript, Malware, Node.js, npm security, OpenSourceMalware, PolinRider, remote access trojan, Socket, ViteVenom

Post navigation

Previous Post: Critical NGINX Vulnerability Enables Remote Code Execution
Next Post: OpenAI Releases Codex Security Tool to Enhance Code Safety

Related Posts

Researchers Find Way to Shut Down Cryptominer Campaigns Using Bad Shares and XMRogue Researchers Find Way to Shut Down Cryptominer Campaigns Using Bad Shares and XMRogue The Hacker News
Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs The Hacker News
Armored Likho’s BusySnake Threatens Government and Energy Sectors Armored Likho’s BusySnake Threatens Government and Energy Sectors The Hacker News
DoJ Seizes Cloud Account in Major Cybercrime Case DoJ Seizes Cloud Account in Major Cybercrime Case The Hacker News
New Android Car Malware Exploits Update Systems New Android Car Malware Exploits Update Systems The Hacker News
Critical Metabase Flaw Exploited, Urgent Patch Released Critical Metabase Flaw Exploited, Urgent Patch Released The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit RubyGems in Massive Package Upload
  • CISA Alerts on GitLab Vulnerability Exploitation
  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit RubyGems in Massive Package Upload
  • CISA Alerts on GitLab Vulnerability Exploitation
  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark