WEDNESDAY, JULY 29, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 3h ago

Compromised npm Packages Deliver RAT to Node.js Projects

By Meridian48 News Desk · Summarised from The Hacker News ·

Two beta versions of npm packages @joyfill/layouts and @joyfill/components were compromised to deploy a remote access trojan. The malicious code executes upon import, decrypting and running the DEV#POPPER RAT. Developers using these versions should rotate credentials and audit systems.

Meridian48 take
The attack highlights the supply-chain risk in npm's beta release channels, where less scrutiny can hide malware.
Read the full reporting
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js →
The Hacker News
npm-supply-chainremote-access-trojan
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan