Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Reported 29 Jul 2026 by otx · Severity: medium
Two npm beta releases in the @joyfill namespace were compromised with an import-time JavaScript implant that uses blockchain transactions on Tron, Aptos, and BNB Smart Chain to retrieve encrypted payloads. The malicious code leads to a 77 KB Node.js remote-access trojan identifie