Joyfill npm beta releases carried a DEV#POPPER RAT
2026-07-28 • Isotope13 •
Two Joyfill npm prereleases published on 2026-07-28 contained an obfuscated DEV#POPPER-family RAT that executed when applications imported the packages, bypassing protections focused on npm install scripts. The implant obtained rotating command-and-control information through Tron, Aptos, and BSC transactions before opening a Socket.IO remote-access channel and deploying a Python credential stealer. It supported shell execution, file operations, clipboard theft, and collection of browser, wallet-extension, and Git credentials, while modifying VS Code and npm tooling for persistence. SafeDep tracks the blockchain dead-drop loader as PolinRider, providing an indirect link to the DPRK-associated Contagious Interview ecosystem.