Back to Feed
Supply ChainJul 28, 2026

Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

Two npm beta releases compromised to deliver DEV#POPPER RAT and OmniStealer malware.

Summary

Two beta releases of Joyfill's npm packages, @joyfill/layouts and @joyfill/components, were compromised to deliver the DEV#POPPER remote access trojan. The malware uses blockchain transactions for C2 communication and can execute arbitrary code, steal credentials, and persist on developer systems. A parallel payload delivers an infostealer, potentially OmniStealer, which targets browser data, Git credentials, and other sensitive information.

Full text

Security News/ResearchFake Corepack Site Distributes Infostealer and Proxyware to DevelopersA fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.By Kirill Boychenko, Sarah Gooding - Jul 24, 2026

Indicators of Compromise

  • ip — 23.27.13.43
  • domain — api.trongrid.io
  • domain — bsc-dataseed.binance.org
  • hash_sha256 — 26e679eaf1e9baeb7c55eb48db482301171d4d26e1728544b23734a90dc70e1b
  • hash_sha256 — 2cfede38fb121a71a2f3607474aa8cd588a99f51b37e5e6f0d8cb789fa275032
  • hash_sha256 — 36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c
  • mitre_attack — T1195.002
  • mitre_attack — T1027
  • mitre_attack — T1059.007
  • mitre_attack — T1059.006
  • mitre_attack — T1105
  • mitre_attack — T1115

Entities

DEV#POPPER RAT (product)OmniStealer (product)npm (technology)Node.js (technology)JavaScript (technology)Python (technology)