Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Brief
Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions. Static analysis shows that its primary branch reaches a 77 KB Node. js remote-access trojan. A parallel branch launches a detached Node. js process, requests a separate boot payload from 23[. ]27[. ]13[.
]43/$/boot , sends the marker header Sec-V: A9-0135-3 , decrypts the response, and evaluates it.
Joyfill provides software development kits for embedding forms, documents, and PDFs into web and mobile applications. @joyfill/components supplies the React UI components used to build, render, and edit these experiences, while @joyfill/layouts manages their page and field layouts.
Each package receives approximately 16,000 weekly downloads on npm.
