Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Compromised npm Packages Distribute RAT via Node.js

Compromised npm Packages Distribute RAT via Node.js

Posted on July 29, 2026 By CWS

Two npm packages in the @joyfill namespace have been discovered to contain remote access trojan (RAT) malware. These compromised beta versions aim to infect systems using the Node.js environment with malicious code linked to the DEV#POPPER malware family.

Affected Packages and Malware Delivery

The impacted packages include @joyfill/[email protected] and @joyfill/[email protected]. An analysis by Socket revealed that these packages employ a JavaScript implant activated during import, resolving encrypted code through transactions on the Tron, Aptos, and BNB Smart Chain blockchains.

This method differs from typical malicious packages, which usually activate via npm lifecycle hooks. Instead, the JavaScript implant executes as soon as the Node.js loads the CommonJS package entry point, indicating a sophisticated attack strategy.

Blockchain Utilization and Threat Analysis

The attack employs a multi-blockchain resolver structure, previously associated with a threat group known as PolinRider, and related to Contagious Interview. This approach enables operational flexibility, allowing payload changes without the need to update package versions.

Earlier reports by Checkmarx and OpenSourceMalware identified similar strategies in the ViteVenom campaign, targeting Vite frontend tooling with a tiered blockchain C2 infrastructure. This method delivers RATs capable of reverse shells, credential theft, and persistent backdoor injections.

Payload Execution and Developer Precautions

The malware initiates with a JavaScript loader that retrieves a secondary malware stage named “clientCode” through blockchain resolution. A separate Node.js process also engages a different IP address to execute additional code.

Developers using these packages should remove affected versions from their systems, including lockfiles, caches, and build images. It’s crucial to switch to a verified version and update credentials to mitigate risks.

Socket advises that the @joyfill/layouts package poses a threat of arbitrary code execution, affecting development environments, CI runners, and more. The ultimate payload can collect host data, establish remote connections, and execute various commands, posing significant security risks.

The incident highlights ongoing cybersecurity challenges, emphasizing the need for vigilance in package management and the importance of maintaining secure development practices.

The Hacker News Tags:Blockchain, Checkmarx, Contagious Interview, Cybersecurity, DEV#POPPER, JavaScript, Malware, Node.js, npm security, OpenSourceMalware, PolinRider, remote access trojan, Socket, ViteVenom

Post navigation

Previous Post: Critical NGINX Vulnerability Enables Remote Code Execution
Next Post: OpenAI Releases Codex Security Tool to Enhance Code Safety

Related Posts

38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases The Hacker News
Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution The Hacker News
GitHub Copilot Generates Harmful Code Despite Refusals GitHub Copilot Generates Harmful Code Despite Refusals The Hacker News
Critical RefluXFS Linux Vulnerability Exposes Systems Critical RefluXFS Linux Vulnerability Exposes Systems The Hacker News
Critical Security Threats and Global Cyber Developments Critical Security Threats and Global Cyber Developments The Hacker News
AI Is Transforming Cybersecurity Adversarial Testing AI Is Transforming Cybersecurity Adversarial Testing The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Releases Codex Security Tool to Enhance Code Safety
  • Compromised npm Packages Distribute RAT via Node.js
  • Critical NGINX Vulnerability Enables Remote Code Execution
  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Releases Codex Security Tool to Enhance Code Safety
  • Compromised npm Packages Distribute RAT via Node.js
  • Critical NGINX Vulnerability Enables Remote Code Execution
  • Chrome Extension Secretly Collects AI Interactions
  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark