Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Summary
Two beta release versions of npm packages within the @joyfill namespace have been compromised. These packages contain an import-time JavaScript implant that executes a remote access trojan (RAT) associated with the DEV#POPPER malware family when imported into a Node.js environment.
IFF Assessment
The discovery of a RAT hidden within legitimate npm packages poses a direct threat to developers and organizations relying on these dependencies, increasing the risk of system compromise.
Defender Context
This incident highlights the persistent supply chain risk associated with third-party code dependencies. Developers should exercise extreme caution when incorporating new or updated packages, especially from less established namespaces, and consider implementing robust dependency scanning and software composition analysis (SCA) tools.