Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Summary

Two beta release versions of npm packages within the @joyfill namespace have been compromised. These packages contain an import-time JavaScript implant that executes a remote access trojan (RAT) associated with the DEV#POPPER malware family when imported into a Node.js environment.

IFF Assessment

FOE

The discovery of a RAT hidden within legitimate npm packages poses a direct threat to developers and organizations relying on these dependencies, increasing the risk of system compromise.

Defender Context

This incident highlights the persistent supply chain risk associated with third-party code dependencies. Developers should exercise extreme caution when incorporating new or updated packages, especially from less established namespaces, and consider implementing robust dependency scanning and software composition analysis (SCA) tools.

Read Full Story →