Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
2026-07-28 • Step Security •
https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise
Malicious prerelease builds of `@joyfill/components` and `@joyfill/layouts` executed an obfuscated Node.js loader when imported, bypassing protections focused on npm installation scripts. The implant used blockchain transactions to resolve later stages, deployed a Socket.IO remote-access trojan, injected persistence into developer tools and the global npm CLI, and staged a Python credential stealer. StepSecurity identified six affected versions and advised treating any environment that imported them as compromised, removing the packages, inspecting persistence targets, and rotating exposed credentials.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 166.88.134.62 | 2026-07-28 | 2026-07-29 |
| WALLET | TA48dct6rFW8BXsiLAtjFaVFoSuryMj… | 2026-06-16 | 2026-07-29 |
| WALLET | TXfxHUet9pJVU1BgVkBAbrES4YUc1nG… | 2026-03-06 | 2026-07-29 |
| WALLET | TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7… | 2026-03-06 | 2026-07-29 |
| IPv4 | 198.105.127.210 | 2026-03-05 | 2026-07-29 |
| IPv4 | 23.27.202.27 | 2025-10-20 | 2026-07-29 |
| HASH | 36ff00b45e67baa7e3674b0c80f48e8… | 2026-07-28 | 2026-07-28 |
| HASH | 26351aed0397158d3a3b8cc8fd3047d… | 2026-07-28 | 2026-07-28 |
| IPv4 | 23.27.13.43 | 2026-07-28 | 2026-07-28 |