Security · 3h ago
Compromised npm Packages Deliver RAT to Node.js Projects
Two beta versions of npm packages @joyfill/layouts and @joyfill/components were compromised to deploy a remote access trojan. The malicious code executes upon import, decrypting and running the DEV#POPPER RAT. Developers using these versions should rotate credentials and audit systems.
Meridian48 take
The attack highlights the supply-chain risk in npm's beta release channels, where less scrutiny can hide malware.
Read the full reporting
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js →
The Hacker News
npm-supply-chainremote-access-trojan