The record
Written from the 1 report below. Nothing here is unsourced.
- Two compromised beta versions of npm packages in the @joyfill namespace deliver a remote access trojan linked to the DEV#POPPER malware family when loaded into Node.js environments.
- The malware uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to fetch its encrypted payload, which can execute commands, upload files, read clipboard data, and steal credentials, browser data, Git and GitHub configurations.
- Socket says the packages are tied to the same North Korean threat operation behind the earlier ViteVenom campaign.
- Developers who installed the affected versions are advised to remove them from lockfiles, caches, and build artifacts, pin to verified versions, and rotate credentials.
What to watch next
- Investigation into how the malicious code was injected — developer workstation, repository, CI environment, or publishing credentials remains unclear
- Possible further compromised npm packages published by the same npm identity
- Continued activity from the North Korean cluster, including new iterations of OmniStealer and related payloads
Coverage1
1 report
English national1
All filed from India
Named North Korea · DEV#POPPER · @joyfill/components · @joyfill/layouts · Node.js · npm · OmniStealer · PolinRider · ViteVenom · Aptos · Checkmarx · eSentire · North Korean threat actors
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
