Joyfill npm Packages Compromised with Blockchain C2 Loader
2026-07-29 • Safe Dep •
Two malicious beta releases in the legitimate `@joyfill` npm scope executed an obfuscated loader when applications imported their production bundles. The loader resolved encrypted payloads through two successive Tron-to-BSC transaction chains, selected C2 infrastructure according to a campaign marker, and ultimately delivered a compressed RAT client. SafeDep found that the blockchain infrastructure and stage 3 bot fingerprints matched its earlier `astro.config.mjs` and PolinRider analysis, although the article did not explicitly state a DPRK attribution. The packages were unpublished after roughly ten hours but remained available through some registry mirrors.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| WALLET | 0x9bc1355344b54dedf3e44296916ed… | 2026-07-28 | 2026-07-29 |
| HASH | bcc93dc55bc7daedf4ca57254f0e7a7… | 2026-07-28 | 2026-07-29 |
| HASH | adc4af90540d33cd1e98f44b51482ae… | 2026-07-28 | 2026-07-29 |
| IPv4 | 166.88.134.62 | 2026-07-28 | 2026-07-29 |
| WALLET | TA48dct6rFW8BXsiLAtjFaVFoSuryMj… | 2026-06-16 | 2026-07-29 |
| WALLET | TXfxHUet9pJVU1BgVkBAbrES4YUc1nG… | 2026-03-06 | 2026-07-29 |
| WALLET | TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7… | 2026-03-06 | 2026-07-29 |
| IPv4 | 198.105.127.210 | 2026-03-05 | 2026-07-29 |
| IPv4 | 23.27.202.27 | 2025-10-20 | 2026-07-29 |