Joyfill

#Joyfill • 2026-07

🇺🇸 United States

On July 28, 2026, malicious beta versions of @joyfill/components and @joyfill/layouts were published to npm with an obfuscated implant embedded in their distribution bundles. Importing an affected package—not merely installing it—triggered a blockchain-resolved loader that deployed a Node.js remote-access trojan, established persistence in developer tools and the global npm CLI, and could stage credential theft, so affected developer and build environments had to be treated as compromised. Code and infrastructure overlapped with PolinRider and DEV#POPPER activity.

Related Actors

Polin Rider

Open Source Malware

PolinRider is the name OpenSourceMalware gave to a 2026 supply-chain campaign it attributes to a North Korean, Lazarus Group-linked threat actor that implants malicious JavaScript into open-source projects on GitHub and npm. Researchers describe it as a parallel or sub-campaign of the broader Contagious Interview activity, noting it initially made use of credentials stolen through a related campaign called TasksJacker. The threat actor forks popular repositories or compromises developers' own repositories, then appends obfuscated JavaScript to frequently executed but rarely reviewed build and configuration files, such as PostCSS, Tailwind CSS, and ESLint configuration files, as well as hiding payloads inside font files. Malicious npm packages were also published to distribute the same payload. The campaign primarily compromises individual, often job-seeking, software developers rather than organizations, and researchers observed its confirmed footprint of poisoned repositories grow substantially between March and July 2026, with targeting spanning ecosystems including Visual Studio Code, Apache Superset, Rails, LangFlow, and Expo.

PolinRider: DPRK Threat Actor Implants Malware in…
Associated with: Contagious Interview
First seen: 2026-03 • Last seen: 2026-08

Related Reports

« Back