Joyfill npm Packages Compromised with Blockchain C2 Loader

2026-07-29 Safe Dep

https://safedep.io/joyfill-npm-blockchain-c2-supply-chain

Thumbnail for Joyfill npm Packages Compromised with Blockchain C2 Loader

Two malicious beta releases in the legitimate `@joyfill` npm scope executed an obfuscated loader when applications imported their production bundles. The loader resolved encrypted payloads through two successive Tron-to-BSC transaction chains, selected C2 infrastructure according to a campaign marker, and ultimately delivered a compressed RAT client. SafeDep found that the blockchain infrastructure and stage 3 bot fingerprints matched its earlier `astro.config.mjs` and PolinRider analysis, although the article did not explicitly state a DPRK attribution. The packages were unpublished after roughly ten hours but remained available through some registry mirrors.

Indicators of Compromise

Type Value First Seen Last Seen
WALLET 0x9bc1355344b54dedf3e44296916ed… 2026-07-28 2026-07-29
HASH bcc93dc55bc7daedf4ca57254f0e7a7… 2026-07-28 2026-07-29
HASH adc4af90540d33cd1e98f44b51482ae… 2026-07-28 2026-07-29
IPv4 166.88.134.62 2026-07-28 2026-07-29
WALLET TA48dct6rFW8BXsiLAtjFaVFoSuryMj… 2026-06-16 2026-07-29
WALLET TXfxHUet9pJVU1BgVkBAbrES4YUc1nG… 2026-03-06 2026-07-29
WALLET TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7… 2026-03-06 2026-07-29
IPv4 198.105.127.210 2026-03-05 2026-07-29
IPv4 23.27.202.27 2025-10-20 2026-07-29

Related Actors

Related Reports

« Back