Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
CYBERSECURITY FEATURED ANALYSIS

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

BY

The Hacker News

SOURCE

The Hacker News

DATE

READ

1 min read

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows …

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages “contain an import-time JavaScript implant that resolves encrypted code