← Back to feed
cybersecurity1 source · 2h ago

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Two compromised npm packages in the @joyfill namespace deliver a remote access trojan associated with DEV#POPPER when imported into Node.js environments.

AffectedNorth Korea DEV#POPPER @joyfill/components @joyfill/layouts Node.js npm OmniStealer PolinRider ViteVenom Aptos Checkmarx eSentire North Korean threat actors
1 outlet · 1 origin · Balanced
India × 1

No Reader read of this story yet.

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

Perspective analysis pending — it generates as coverage from more origins arrives.

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

Impact analysis pending.

Sources (1)

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js — Prism