Threat reportSupply ChainTL-2026-1746

Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

criticalACTIVE

Two Joyfill npm Beta Releases Compromised to Deliver (TL-2026-1746), also tracked as Joyfill npm Supply Chain Compromise, is a critical-severity supply-chain compromise, first published 2026-07-28 and last reviewed 2026-08-13. It is attributed to Contagious Interview - G1052 (North Korea) with high confidence, affects Joyfill @joyfill/layouts (npm package), maps to 37 MITRE ATT&CK techniques (T1005, T1008, T1027), and is covered by 9 detection rules and 61 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
37MITRE ATT&CK
Actors
1Contagious Interview - G1052
Detection rules
9SPL · KQL · Sigma
IOCs
61Indicators of compromise

Key facts for TL-2026-1746

Threat ID
TL-2026-1746
Also known as
Joyfill npm Supply Chain Compromise
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
Contagious Interview - G1052
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, softwaredevelopment, energy, utilities, cryptocurrency
Target regions
Global
Detection rules
9
Indicators of compromise
61
Updates
2026-08-13 · 5 updates · revalidated 3×

Malware and tooling in Two Joyfill npm Beta Releases Compromised to Deliver

Malware and tooling: DEV#POPPER, OmniStealer, PolinRider, Obfuscator.io

How Two Joyfill npm Beta Releases Compromised to Deliver works

Beta releases of two npm packages in the @joyfill namespace (@joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4), published July 28, 2026 by the same npm identity, contain an import-time JavaScript implant that resolves an encrypted 77KB Node.js RAT via Tron/Aptos/BNB Smart Chain transactions (no traditional C2 for stage-1 delivery), then stages an 82KB Python infostealer targeting browser data, Git credentials, and 200+ wallet/password-manager extensions.

On 2026-07-28, the Socket Threat Research Team identified two malicious beta releases in the @joyfill npm namespace: @joyfill/layouts@0.1.2-2773.beta.0 (published 10:54:57 UTC) and @joyfill/components@4.0.0-rc24-2773-beta.4 (published 11:03:59 UTC), both published by the same npm identity using Node.js 18.20.0 and npm 10.5.0. The malicious code was present in the published bundle at publish time rather than injected via a compromised install script, indicating either maintainer credential compromise or compromised build/CI infrastructure upstream of `npm publish`.

The implant executes at import time (no install-script trigger, so `npm install --ignore-scripts` provides no protection) and runs a three-stage architecture. Stage 0 (Bootstrap) forks both an in-process path and a detached `child_process.spawn({ detached: true })` path. Stage 1 (Blockchain Dispatch) resolves encrypted payload material with no reliance on conventional DNS/HTTP C2 infrastructure: it reads Tron account transactions (`TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP` in-process, `TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG` detached), falls back to Aptos account transactions, and to BNB Smart Chain transactions retrieved via `eth_getTransactionByHash`, decoding and XOR-decrypting the transaction payload with path-specific keys. This blockchain-as-dead-drop-resolver pattern makes takedown far harder than IP/domain blocklisting, since the resolver infrastructure is a public, permissionless ledger. Stage 2 delivers the 77KB Node.js RAT (SHA-256 26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18) via a second-tier blockchain resolution. A parallel detached "boot downloader" process independently requests `23.27.13.43/$/boot` with a custom `Sec-V: A9-0135-3` header and decrypts the response with the key `ThZG+0jfXE6VAGOJ`.

The delivered RAT exposes a socket.io-style command vocabulary (`ss_eval`/`ss_eval64` for JS/base64 execution, `ss_upf`/`ss_upd` for file transfer, `ss_dir` for directory enumeration, `ss_fcd` for file modification/traversal), reads the OS clipboard (PowerShell on Windows, `pbpaste`/`xclip`/`xsel` on Unix), enumerates Windows processes, and calls `ip-api.com` for public-IP fingerprinting. It persists by patching Node.js-hosted developer tools directly: `@vscode/deviceid` (covering VS Code, Cursor, and Antigravity), the Discord Desktop core module, GitHub Desktop's `resources/app/main.js`, and the global npm CLI at `node_modules/npm/lib/cli.js` — guaranteeing re-execution on next launch of any of those apps. Injected code carries recognizable markers (`/*C250617A*/`, `/*RS260605*/`).

The `/$/boot` response delivers a second payload: an 82KB Python infostealer (SHA-256 36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c) that harvests Windows Credential Manager and Linux Secret Service entries, Chromium/Firefox storage, wallet-manager and password-manager browser extensions, Git credentials and GitHub CLI config, and VS Code storage — staging everything as an AES-encrypted ZIP (password `,./,./,./`) under `%USERPROFILE%\.npm` (Windows) or `/tmp/.npm` (Linux/macOS) before optional Telegram-bot exfiltration. Socket assesses "medium likelihood" this is an iteration of the OmniStealer family.

Attribution ties this incident to the DEV#POPPER malware family via shared structural fingerprints: the PolinRider-family multi-chain loader structure (`rmcej%otb%` marker, shared global-naming conventions), the identical `Sec-V` header scheme and `/$/boot` endpoint design, the `ss_*` socket.io command vocabulary, and matching XOR key derivation. DEV#POPPER was first documented by eSentire's Threat Response Unit (TRU) in a February 2026 incident on an Energy/Utilities/Waste customer host, where a victim cloned a weaponized GitHub repository ("ShoeVista", disguised as an e-commerce platform), launched its frontend, and triggered a Node.js backdoor hidden by whitespace padding in `frontend/tailwind.config.js`. eSentire attributes DEV#POPPER with high confidence to a North Korean state-sponsored APT, noting the RAT primarily targets macOS (also Windows/Linux) and is used to steal cryptocurrency wallets and developer secrets (source-code credentials, API keys, cloud tokens). Network overlap between the Joyfill incident's C2 set (166.88.134.62, 23.27.13.43, 198.105.127.210, 23.27.202.27) and eSentire's documented DEV#POPPER infrastructure (23.27.20.143 and 23.27.202.27 both on ASN 149440, Evoxt Sdn. Bhd.; plus 136.0.9.8) corroborates shared operator infrastructure.

The delivery mechanism also matches the broader PolinRider campaign that Socket disclosed on 2026-07-01: a North Korea-linked (Contagious Interview / Famous Chollima cluster) operation that has compromised 108 unique packages/extensions (162 malicious release artifacts) across npm (19), Packagist (10), Go modules (61), and Chrome Web Store (1), via maintainer/build-infrastructure compromise on accounts such as `Xpos587` (GitHub) and the `7span`/`sevenspan` namespace (GitHub/Packagist). PolinRider's loader reaches TRON, Aptos, and BNB Smart Chain RPC infrastructure to retrieve and XOR-decrypt second-stage material before executing it with `eval()`, and has been observed delivering both DEV#POPPER and OmniStealer — the loader design means it is capable of delivering additional payload families. As of a 2026-07-04 report, PolinRider-linked activity had touched 1,951 public GitHub repositories across 1,047 owners and had merged with a related VS Code task-hijacking cluster ("TaskJacker") that drops malicious `runOn: folderOpen` task files into existing repositories. Socket assesses the campaign as ongoing and expects continued new package releases as the actor rotates compromised maintainer accounts.

Each affected @joyfill package averages roughly 16,000 weekly npm downloads; exposure is limited to installs that pinned or floated onto the specific malicious beta/rc tags. No CVE has been assigned — this is a malicious-package supply-chain incident rather than a software vulnerability, and CVSS scoring is not applicable.

MITRE ATT&CK techniques used in TL-2026-1746

Collection

T1005 Data from Local System; T1074 Data Staged; T1115 Clipboard Data; T1119 Automated Collection; T1560 Archive Collected Data

Command and Control

T1008 Fallback Channels; T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1614 System Location Discovery

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1129 Shared Modules; T1204 User Execution

Initial Access

T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship

Credential Access

T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Persistence

T1554 Compromise Host Software Binary

Resource Development

T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1587 Develop Capabilities

Impact

T1657 Financial Theft

Affected products and versions in Two Joyfill npm Beta Releases Compromised to Deliver

  • Joyfill — @joyfill/layouts (npm package)
    Vulnerable versions: 0.1.2-2773.beta.0
    Fixed in: 0.1.1
  • Joyfill — @joyfill/components (npm package)
    Vulnerable versions: 4.0.0-rc24-2773-beta.4
    Fixed in: 4.0.0-rc24

Remediation for Two Joyfill npm Beta Releases Compromised to Deliver

Patches

  • Upgrade to @joyfill/layouts@0.1.1
  • Upgrade to @joyfill/components@4.0.0-rc24 (non-beta tag)

Immediate actions

  • Remove @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 from all lockfiles, CI caches, and container images immediately
  • Pin/downgrade to the clean releases: @joyfill/layouts@0.1.1 and @joyfill/components@4.0.0-rc24
  • Block the identified C2 and boot infrastructure at network egress and registry proxies: 166.88.134.62, 23.27.13.43, 198.105.127.210, 23.27.202.27, 23.27.20.143, 136.0.9.8
  • Treat any host that resolved a malicious beta install as compromised (not merely at-risk): rotate npm tokens, Git credentials, cloud/API keys, and password-manager master credentials; re-image if wallet extensions were present

Workarounds

  • Avoid installing any beta/rc-tagged @joyfill package versions until publisher identity is re-verified
  • `npm install --ignore-scripts` provides no protection — the implant executes at import time, not via install lifecycle scripts

Longer-term hardening

  • Monitor developer workstation and CI-runner egress for outbound calls to Tron/Aptos/BSC RPC endpoints (api.trongrid.io, fullnode.mainnet.aptoslabs.com, bsc-dataseed.binance.org, bsc-rpc.publicnode.com) as a blockchain-dead-drop-resolver detection signal
  • Enforce npm publish provenance attestation and mandatory 2FA on maintainer accounts to reduce the maintainer/build-infrastructure compromise attack surface exploited across the PolinRider campaign
  • Integrity-monitor Node.js-hosted developer tools (VS Code/Cursor/Antigravity's @vscode/deviceid, Discord Desktop core module, GitHub Desktop resources/app/main.js, global npm CLI cli.js) for unauthorized modification or injection markers (/*C250617A*/, /*RS260605*/)
  • Scan repositories for VS Code task files with runOn: folderOpen configurations (TaskJacker pattern) that auto-execute on repo open

Weaknesses (CWE) in Two Joyfill npm Beta Releases Compromised to Deliver

CWE-506, CWE-829, CWE-494, CWE-1357

Timeline of Two Joyfill npm Beta Releases Compromised to Deliver

  • Securonix first documents the DEV#POPPER campaign: North Korea-linked actors using fake job-interview lures to deliver a Python-based RAT to software developers, predating any previously recorded timeline entry for this malware family.
  • Anti-dated malicious commits are later found inserted into 7span/sevenspan repositories, part of the precursor activity for the PolinRider campaign that would later be linked to this incident's malware family.
  • eSentire's Threat Response Unit observes DEV#POPPER RAT and OmniStealer on an Energy, Utilities, and Waste sector customer host, delivered via the weaponized 'ShoeVista' GitHub repository.
  • eSentire publishes technical analysis of DEV#POPPER RAT and OmniStealer, attributing the malware with high confidence to a North Korean state-sponsored APT and releasing the DEV#STOPPER.js deobfuscation tool.
  • Partial remediation occurs on compromised PolinRider-linked repositories; malicious font files used for payload staging are removed.
  • Synchronized compromise of multiple repositories under the Xpos587 GitHub account occurs at approximately 10:00 UTC, part of the expanding PolinRider campaign.
  • A related cluster of seven malicious Vite-ecosystem npm packages (ViteVenom) begins publication, later found to share identical Tron/Aptos/BSC wallets and XOR decryption keys with the joyfill implant infrastructure.
  • Socket publishes its PolinRider campaign report, documenting 108 compromised packages/extensions (162 malicious release artifacts) across npm, Packagist, Go modules, and Chrome, using the same Tron/Aptos/BSC blockchain-dispatch loader mechanism.
  • Final ViteVenom typosquat package published, completing the seven-package cluster tied to the joyfill compromise by shared blockchain C2 infrastructure.
  • Mainstream security press (The Hacker News, DevOps.com, Rescana) reports on the PolinRider campaign, noting it has touched 1,951 public GitHub repositories across 1,047 owners and merged with the TaskJacker VS Code task-hijacking cluster.
  • Follow-on malicious beta tags are republished under the same implant architecture: @joyfill/layouts@0.1.2-2773.beta.1/.beta.2 and @joyfill/components@4.0.0-rc24-2773-beta.5/.beta.6.
  • The Socket Threat Research Team publishes disclosure of the Joyfill npm compromise, documenting the RAT/infostealer chain and attributing it to the DEV#POPPER/PolinRider malware family via shared loader structure, header scheme, and C2 infrastructure overlap.
  • @joyfill/layouts@0.1.2-2773.beta.0 is published to the npm registry containing the import-time blockchain-dispatch implant.
  • @joyfill/components@4.0.0-rc24-2773-beta.4 is published to the npm registry by the same identity, containing the same implant.
  • The Hacker News and multiple additional outlets (StepSecurity, gbhackers, Vulert, Mallory) publish coverage of the joyfill npm compromise specifically, with remediation guidance.
  • Socket's Threat Research Team publishes full technical analysis of the joyfill implant's blockchain C2 resolution chain, worm self-propagation, and CI/sandbox-evasion logic.

Update history for TL-2026-1746

Sources cited for Two Joyfill npm Beta Releases Compromised to Deliver

Detection coverage for TL-2026-1746

As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1746 across Splunk SPL, Microsoft KQL and Sigma, covering 61 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
61 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1746

4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats