Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

2026-07-28 Step Security

https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise

Thumbnail for Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

Malicious prerelease builds of `@joyfill/components` and `@joyfill/layouts` executed an obfuscated Node.js loader when imported, bypassing protections focused on npm installation scripts. The implant used blockchain transactions to resolve later stages, deployed a Socket.IO remote-access trojan, injected persistence into developer tools and the global npm CLI, and staged a Python credential stealer. StepSecurity identified six affected versions and advised treating any environment that imported them as compromised, removing the packages, inspecting persistence targets, and rotating exposed credentials.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 166.88.134.62 2026-07-28 2026-07-29
WALLET TA48dct6rFW8BXsiLAtjFaVFoSuryMj… 2026-06-16 2026-07-29
WALLET TXfxHUet9pJVU1BgVkBAbrES4YUc1nG… 2026-03-06 2026-07-29
WALLET TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7… 2026-03-06 2026-07-29
IPv4 198.105.127.210 2026-03-05 2026-07-29
IPv4 23.27.202.27 2025-10-20 2026-07-29
HASH 36ff00b45e67baa7e3674b0c80f48e8… 2026-07-28 2026-07-28
HASH 26351aed0397158d3a3b8cc8fd3047d… 2026-07-28 2026-07-28
IPv4 23.27.13.43 2026-07-28 2026-07-28

Related Reports

« Back