Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations.
AI Analysis
Technical Summary
Two npm beta releases under the @joyfill namespace were compromised by an import-time JavaScript implant that leverages blockchain transactions on Tron, Aptos, and BNB Smart Chain to fetch encrypted payloads. This implant delivers a 77 KB Node.js remote access trojan named DEV#POPPER, which uses Socket.IO connections for remote control capabilities including command execution, file upload, clipboard reading, and persistence via developer tools. A secondary execution path downloads an 82 KB Python infostealer identified as OmniStealer, which targets sensitive data such as browser credentials, Git configurations, and wallet extensions. The affected versions are @joyfill/layouts 0.1.2-2773.beta.0 and @joyfill/components 4.0.0-rc24-2773-beta.4. The loader code shows exact overlap with the PolinRider malware family and DEV#POPPER operations. Approximately 16,000 weekly downloads increase exposure risk. No vendor advisory or patch information is available.
Potential Impact
The compromise results in the delivery of a remote access trojan capable of full remote control over infected systems, including command execution, file manipulation, clipboard access, and persistence. Additionally, an infostealer targets sensitive developer-related data such as browser credentials, Git configurations, and wallet extensions, potentially leading to credential theft and further compromise. The supply chain nature of the attack increases risk to developers and downstream users relying on these npm packages.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid using the affected beta versions of @joyfill/layouts and @joyfill/components. Review and audit dependencies for suspicious activity and consider removing or replacing compromised packages. Monitor for unusual network connections and behaviors consistent with remote access trojans. No official fix or patch links are currently provided.
Indicators of Compromise
- ip: 23.27.202.27
- ip: 198.105.127.210
- hash: 2cfede38fb121a71a2f3607474aa8cd588a99f51b37e5e6f0d8cb789fa275032
- ip: 166.88.134.62
- ip: 23.27.13.43
- hash: 26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18
- hash: 36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c
- hash: adc4af90540d33cd1e98f44b51482ae9250fbeb97d6f8d7841c81b618cb2c6e6
- hash: 8e8b90dedd456ded0c5748119836e1ca1066112bc569c1b41ca70eb931d1d4dc
- hash: 5f6a92006ca2ea4b464d66fb41af777edce7296939a7c6ee491e2b3cbfe09848
- hash: bcc93dc55bc7daedf4ca57254f0e7a7f1c40e09851eab98fe10cde801982db17
- hash: 1352ad22c99983d91e600348b7cbf58235131b1ee34cea9f09623206d5b7dea7
- hash: 67c6ef602cc850f10d935fee53fa40440df841adf081563bf4fc2631a71249ce
- hash: c5742ea1875ecd2360022624149994909cd0546e221e4203dffd01f48de45469
- hash: cb46f12d70824ea24ed1f8bcf45bf3f86680e02a9089aafc03b27f691be57be3
- hash: f452f9cfa539f4a1fe25187a99a484391290d5dbaa422ba455edf6b04f81b7d1
- hash: 78f0de8682e0e894a5784eb7e95db4da6088f528918ca3107dd1e76f80a561d8
- hash: ae7565109fd01b88d82acf7f73ab20709cbc2c9f26fdea13e429ccc87a55d4fb
- hash: 26e679eaf1e9baeb7c55eb48db482301171d4d26e1728544b23734a90dc70e1b
- hash: b7c8c84d1729e78ca9d64d1d6dd97fe4
- hash: e147076dd588df4e2bc9db25fcc306fb34a04a55
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Description
Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identified as DEV#POPPER, which establishes Socket.IO connections for remote control and can execute commands, upload files, read clipboard data, and persist through developer tools. A parallel execution branch downloads additional payloads including an 82 KB Python infostealer assessed to be OmniStealer, targeting browser credentials, Git configurations, and wallet extensions. The compromise affected @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4, with approximately 16,000 weekly downloads. The loader exhibits exact code overlap with the PolinRider family and DEV#POPPER operations.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Two npm beta releases under the @joyfill namespace were compromised by an import-time JavaScript implant that leverages blockchain transactions on Tron, Aptos, and BNB Smart Chain to fetch encrypted payloads. This implant delivers a 77 KB Node.js remote access trojan named DEV#POPPER, which uses Socket.IO connections for remote control capabilities including command execution, file upload, clipboard reading, and persistence via developer tools. A secondary execution path downloads an 82 KB Python infostealer identified as OmniStealer, which targets sensitive data such as browser credentials, Git configurations, and wallet extensions. The affected versions are @joyfill/layouts 0.1.2-2773.beta.0 and @joyfill/components 4.0.0-rc24-2773-beta.4. The loader code shows exact overlap with the PolinRider malware family and DEV#POPPER operations. Approximately 16,000 weekly downloads increase exposure risk. No vendor advisory or patch information is available.
Potential Impact
The compromise results in the delivery of a remote access trojan capable of full remote control over infected systems, including command execution, file manipulation, clipboard access, and persistence. Additionally, an infostealer targets sensitive developer-related data such as browser credentials, Git configurations, and wallet extensions, potentially leading to credential theft and further compromise. The supply chain nature of the attack increases risk to developers and downstream users relying on these npm packages.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid using the affected beta versions of @joyfill/layouts and @joyfill/components. Review and audit dependencies for suspicious activity and consider removing or replacing compromised packages. Monitor for unusual network connections and behaviors consistent with remote access trojans. No official fix or patch links are currently provided.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://socket.dev/blog/joyfill-npm-beta-releases-compromised"]
- Adversary
- null
- Pulse Id
- 6a696c951815449cad089687
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip23.27.202.27 | — | |
ip198.105.127.210 | — | |
ip166.88.134.62 | — | |
ip23.27.13.43 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash2cfede38fb121a71a2f3607474aa8cd588a99f51b37e5e6f0d8cb789fa275032 | — | |
hash26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18 | — | |
hash36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c | — | |
hashadc4af90540d33cd1e98f44b51482ae9250fbeb97d6f8d7841c81b618cb2c6e6 | — | |
hash8e8b90dedd456ded0c5748119836e1ca1066112bc569c1b41ca70eb931d1d4dc | — | |
hash5f6a92006ca2ea4b464d66fb41af777edce7296939a7c6ee491e2b3cbfe09848 | — | |
hashbcc93dc55bc7daedf4ca57254f0e7a7f1c40e09851eab98fe10cde801982db17 | — | |
hash1352ad22c99983d91e600348b7cbf58235131b1ee34cea9f09623206d5b7dea7 | — | |
hash67c6ef602cc850f10d935fee53fa40440df841adf081563bf4fc2631a71249ce | — | |
hashc5742ea1875ecd2360022624149994909cd0546e221e4203dffd01f48de45469 | — | |
hashcb46f12d70824ea24ed1f8bcf45bf3f86680e02a9089aafc03b27f691be57be3 | — | |
hashf452f9cfa539f4a1fe25187a99a484391290d5dbaa422ba455edf6b04f81b7d1 | — | |
hash78f0de8682e0e894a5784eb7e95db4da6088f528918ca3107dd1e76f80a561d8 | — | |
hashae7565109fd01b88d82acf7f73ab20709cbc2c9f26fdea13e429ccc87a55d4fb | — | |
hash26e679eaf1e9baeb7c55eb48db482301171d4d26e1728544b23734a90dc70e1b | — | |
hashb7c8c84d1729e78ca9d64d1d6dd97fe4 | — | |
hashe147076dd588df4e2bc9db25fcc306fb34a04a55 | — |
Threat ID: 6a69eceb9c2644c7f878ace8
Added to database: 07/29/2026, 12:07:07 UTC
Last enriched: 07/29/2026, 14:14:18 UTC
Last updated: 07/30/2026, 03:43:53 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.