← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 28, 2026 · 14:34via Socket Security Blog

Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

Brief

Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions. Static analysis shows that its primary branch reaches a 77 KB Node. js remote-access trojan. A parallel branch launches a detached Node. js process, requests a separate boot payload from 23[. ]27[. ]13[.

]43/$/boot , sends the marker header Sec-V: A9-0135-3 , decrypts the response, and evaluates it.

Joyfill provides software development kits for embedding forms, documents, and PDFs into web and mobile applications. @joyfill/components supplies the React UI components used to build, render, and edit these experiences, while @joyfill/layouts manages their page and field layouts.

Each package receives approximately 16,000 weekly downloads on npm.

Read more on Socket Security Blog