Open the article to view the coverage from IT Security News - cybersecurity, infosecurity news
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
Beta versions of two npm packages from the @joyfill namespace have been compromised and deliver a remote access Trojan. The @joyfill/layouts packages are affected in version 0.1.2-2773.beta.0 and @joyfill/components in version 4.0.0-rc24-2773-beta.4. According to an analysis by the security company Socket, both packages contain a JavaScript malicious code active at import time, which reloads encrypted code via transactions of the blockchains Tro…