Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Compromised npm Packages Distribute RAT via Node.js

Compromised npm Packages Distribute RAT via Node.js

Posted on July 29, 2026 By CWS

Two npm packages in the @joyfill namespace have been discovered to contain remote access trojan (RAT) malware. These compromised beta versions aim to infect systems using the Node.js environment with malicious code linked to the DEV#POPPER malware family.

Affected Packages and Malware Delivery

The impacted packages include @joyfill/[email protected] and @joyfill/[email protected]. An analysis by Socket revealed that these packages employ a JavaScript implant activated during import, resolving encrypted code through transactions on the Tron, Aptos, and BNB Smart Chain blockchains.

This method differs from typical malicious packages, which usually activate via npm lifecycle hooks. Instead, the JavaScript implant executes as soon as the Node.js loads the CommonJS package entry point, indicating a sophisticated attack strategy.

Blockchain Utilization and Threat Analysis

The attack employs a multi-blockchain resolver structure, previously associated with a threat group known as PolinRider, and related to Contagious Interview. This approach enables operational flexibility, allowing payload changes without the need to update package versions.

Earlier reports by Checkmarx and OpenSourceMalware identified similar strategies in the ViteVenom campaign, targeting Vite frontend tooling with a tiered blockchain C2 infrastructure. This method delivers RATs capable of reverse shells, credential theft, and persistent backdoor injections.

Payload Execution and Developer Precautions

The malware initiates with a JavaScript loader that retrieves a secondary malware stage named “clientCode” through blockchain resolution. A separate Node.js process also engages a different IP address to execute additional code.

Developers using these packages should remove affected versions from their systems, including lockfiles, caches, and build images. It’s crucial to switch to a verified version and update credentials to mitigate risks.

Socket advises that the @joyfill/layouts package poses a threat of arbitrary code execution, affecting development environments, CI runners, and more. The ultimate payload can collect host data, establish remote connections, and execute various commands, posing significant security risks.

The incident highlights ongoing cybersecurity challenges, emphasizing the need for vigilance in package management and the importance of maintaining secure development practices.

The Hacker News Tags:Blockchain, Checkmarx, Contagious Interview, Cybersecurity, DEV#POPPER, JavaScript, Malware, Node.js, npm security, OpenSourceMalware, PolinRider, remote access trojan, Socket, ViteVenom

Post navigation

Previous Post: Critical NGINX Vulnerability Enables Remote Code Execution
Next Post: OpenAI Releases Codex Security Tool to Enhance Code Safety

Related Posts

Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp The Hacker News
Microsoft Addresses Active Windows Zero-Day Vulnerability Microsoft Addresses Active Windows Zero-Day Vulnerability The Hacker News
Crypto Wallet Flaw ‘Ill Bloom’ Leads to .1 Million Theft Crypto Wallet Flaw ‘Ill Bloom’ Leads to $3.1 Million Theft The Hacker News
Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts The Hacker News
Helping CISOs Speak the Language of Business Helping CISOs Speak the Language of Business The Hacker News
OkoBot Malware Targets Ledger, Trezor Wallets OkoBot Malware Targets Ledger, Trezor Wallets The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark