VMTech
Discuss a project

Two Joyfill npm Beta Releases Execute a RAT on Import

Two Joyfill npm Beta Releases Execute a RAT on Import

Socket found that two beta releases in the @joyfill namespace were compromised to deliver a remote access trojan. @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 run an implant when Node.js loads their CommonJS entry point. The trigger is the import itself, not an npm lifecycle hook.

How the blockchain dispatch works

The implant obtains a BSC transaction hash from the latest outbound transaction of a hard-coded Tron address. If that fails, an Aptos account supplies the BSC transaction. The package then extracts, decrypts and executes JavaScript carried through this resolver.

One branch recovers a 77 KB JavaScript payload resembling DEV#POPPER. Another launches a detached Node.js process, requests code from 23.27.13[.]43, decrypts it and evaluates it. The process can outlive a build or test command, while blockchain dispatch lets operators switch payloads without publishing a new package version.

RAT and infostealer capabilities

The first path retrieves the obfuscated clientCode Node.js RAT. It reports host details, opens a Socket.IO control channel, runs supplied JavaScript or shell commands, uploads files and reads the clipboard. It skips hosts named github-runner, buildbot, buildkitsandbox and microsoft-standard-WSL2.

The detached path has delivered clientCode and a Python infostealer assessed as an OmniStealer iteration. Targets include browser data, wallet and password-manager extension storage, Git credentials, GitHub tooling, Visual Studio Code data and system credential stores.

Campaign link and containment

Socket attributes the Joyfill releases and ViteVenom to a broader wave of North Korean npm attacks affecting open-source software supply chains. Both belong to one ongoing operation, not separate campaigns. Both versions came from the same npm identity using Node.js 18.20.0 and npm 10.5.0. The source of the injection remains unknown.

Businesses should purge the versions from lockfiles, caches, mirrors, build images and deployment artifacts, pin a verified version, and rotate credentials exposed to the Node.js process. Review developer systems, CI runners, tests, server-side rendering and builds for exposure.

#npmsecurity#supplychain#nodejs#malware
Open analytics
On the site 1 views
min read 2 02.08.2026
Instagram

Two Joyfill npm Beta Releases Execute a RAT on Import

Open the post on Instagram ↗