Joyfill
#Joyfill • 2026-07
🇺🇸 United States
On July 28, 2026, malicious beta versions of @joyfill/components and @joyfill/layouts were published to npm with an obfuscated implant embedded in their distribution bundles. Importing an affected package—not merely installing it—triggered a blockchain-resolved loader that deployed a Node.js remote-access trojan, established persistence in developer tools and the global npm CLI, and could stage credential theft, so affected developer and build environments had to be treated as compromised. Code and infrastructure overlapped with PolinRider and DEV#POPPER activity.
-
4
Related Reports
-
1
Affected Countries
-
2
Months Since