Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Open the article to view the coverage from IT Security News - cybersecurity, infosecurity news
DisclaimerThis story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.

7 Articles

Beta versions of two npm packages from the @joyfill namespace have been compromised and deliver a remote access Trojan. The @joyfill/layouts packages are affected in version 0.1.2-2773.beta.0 and @joyfill/components in version 4.0.0-rc24-2773-beta.4. According to an analysis by the security company Socket, both packages contain a JavaScript malicious code active at import time, which reloads encrypted code via transactions of the blockchains Tro…

The Hacker NewsThe Hacker News
+3 Reposted by 3 other sources

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Open the article to view the coverage from The Hacker News

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • There is no tracked Bias information for the sources covering this story.

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Hacker News broke the news on Wednesday, July 29, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal