Threat reportSupply ChainTL-2026-1746
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Two Joyfill npm Beta Releases Compromised to Deliver (TL-2026-1746), also tracked as Joyfill npm Supply Chain Compromise, is a critical-severity supply-chain compromise, first published 2026-07-28 and last reviewed 2026-08-13. It is attributed to Contagious Interview - G1052 (North Korea) with high confidence, affects Joyfill @joyfill/layouts (npm package), maps to 37 MITRE ATT&CK techniques (T1005, T1008, T1027), and is covered by 9 detection rules and 61 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 37MITRE ATT&CK
- Actors
- 1Contagious Interview - G1052
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 61Indicators of compromise
Key facts for TL-2026-1746
- Threat ID
- TL-2026-1746
- Also known as
- Joyfill npm Supply Chain Compromise
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Contagious Interview - G1052
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, softwaredevelopment, energy, utilities, cryptocurrency
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 61
- Updates
- 2026-08-13 · 5 updates · revalidated 3×
Malware and tooling in Two Joyfill npm Beta Releases Compromised to Deliver
Malware and tooling: DEV#POPPER, OmniStealer, PolinRider, Obfuscator.io
How Two Joyfill npm Beta Releases Compromised to Deliver works
Beta releases of two npm packages in the @joyfill namespace (@joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4), published July 28, 2026 by the same npm identity, contain an import-time JavaScript implant that resolves an encrypted 77KB Node.js RAT via Tron/Aptos/BNB Smart Chain transactions (no traditional C2 for stage-1 delivery), then stages an 82KB Python infostealer targeting browser data, Git credentials, and 200+ wallet/password-manager extensions.
On 2026-07-28, the Socket Threat Research Team identified two malicious beta releases in the @joyfill npm namespace: @joyfill/layouts@0.1.2-2773.beta.0 (published 10:54:57 UTC) and @joyfill/components@4.0.0-rc24-2773-beta.4 (published 11:03:59 UTC), both published by the same npm identity using Node.js 18.20.0 and npm 10.5.0. The malicious code was present in the published bundle at publish time rather than injected via a compromised install script, indicating either maintainer credential compromise or compromised build/CI infrastructure upstream of `npm publish`.
The implant executes at import time (no install-script trigger, so `npm install --ignore-scripts` provides no protection) and runs a three-stage architecture. Stage 0 (Bootstrap) forks both an in-process path and a detached `child_process.spawn({ detached: true })` path. Stage 1 (Blockchain Dispatch) resolves encrypted payload material with no reliance on conventional DNS/HTTP C2 infrastructure: it reads Tron account transactions (`TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP` in-process, `TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG` detached), falls back to Aptos account transactions, and to BNB Smart Chain transactions retrieved via `eth_getTransactionByHash`, decoding and XOR-decrypting the transaction payload with path-specific keys. This blockchain-as-dead-drop-resolver pattern makes takedown far harder than IP/domain blocklisting, since the resolver infrastructure is a public, permissionless ledger. Stage 2 delivers the 77KB Node.js RAT (SHA-256 26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18) via a second-tier blockchain resolution. A parallel detached "boot downloader" process independently requests `23.27.13.43/$/boot` with a custom `Sec-V: A9-0135-3` header and decrypts the response with the key `ThZG+0jfXE6VAGOJ`.
The delivered RAT exposes a socket.io-style command vocabulary (`ss_eval`/`ss_eval64` for JS/base64 execution, `ss_upf`/`ss_upd` for file transfer, `ss_dir` for directory enumeration, `ss_fcd` for file modification/traversal), reads the OS clipboard (PowerShell on Windows, `pbpaste`/`xclip`/`xsel` on Unix), enumerates Windows processes, and calls `ip-api.com` for public-IP fingerprinting. It persists by patching Node.js-hosted developer tools directly: `@vscode/deviceid` (covering VS Code, Cursor, and Antigravity), the Discord Desktop core module, GitHub Desktop's `resources/app/main.js`, and the global npm CLI at `node_modules/npm/lib/cli.js` — guaranteeing re-execution on next launch of any of those apps. Injected code carries recognizable markers (`/*C250617A*/`, `/*RS260605*/`).
The `/$/boot` response delivers a second payload: an 82KB Python infostealer (SHA-256 36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c) that harvests Windows Credential Manager and Linux Secret Service entries, Chromium/Firefox storage, wallet-manager and password-manager browser extensions, Git credentials and GitHub CLI config, and VS Code storage — staging everything as an AES-encrypted ZIP (password `,./,./,./`) under `%USERPROFILE%\.npm` (Windows) or `/tmp/.npm` (Linux/macOS) before optional Telegram-bot exfiltration. Socket assesses "medium likelihood" this is an iteration of the OmniStealer family.
Attribution ties this incident to the DEV#POPPER malware family via shared structural fingerprints: the PolinRider-family multi-chain loader structure (`rmcej%otb%` marker, shared global-naming conventions), the identical `Sec-V` header scheme and `/$/boot` endpoint design, the `ss_*` socket.io command vocabulary, and matching XOR key derivation. DEV#POPPER was first documented by eSentire's Threat Response Unit (TRU) in a February 2026 incident on an Energy/Utilities/Waste customer host, where a victim cloned a weaponized GitHub repository ("ShoeVista", disguised as an e-commerce platform), launched its frontend, and triggered a Node.js backdoor hidden by whitespace padding in `frontend/tailwind.config.js`. eSentire attributes DEV#POPPER with high confidence to a North Korean state-sponsored APT, noting the RAT primarily targets macOS (also Windows/Linux) and is used to steal cryptocurrency wallets and developer secrets (source-code credentials, API keys, cloud tokens). Network overlap between the Joyfill incident's C2 set (166.88.134.62, 23.27.13.43, 198.105.127.210, 23.27.202.27) and eSentire's documented DEV#POPPER infrastructure (23.27.20.143 and 23.27.202.27 both on ASN 149440, Evoxt Sdn. Bhd.; plus 136.0.9.8) corroborates shared operator infrastructure.
The delivery mechanism also matches the broader PolinRider campaign that Socket disclosed on 2026-07-01: a North Korea-linked (Contagious Interview / Famous Chollima cluster) operation that has compromised 108 unique packages/extensions (162 malicious release artifacts) across npm (19), Packagist (10), Go modules (61), and Chrome Web Store (1), via maintainer/build-infrastructure compromise on accounts such as `Xpos587` (GitHub) and the `7span`/`sevenspan` namespace (GitHub/Packagist). PolinRider's loader reaches TRON, Aptos, and BNB Smart Chain RPC infrastructure to retrieve and XOR-decrypt second-stage material before executing it with `eval()`, and has been observed delivering both DEV#POPPER and OmniStealer — the loader design means it is capable of delivering additional payload families. As of a 2026-07-04 report, PolinRider-linked activity had touched 1,951 public GitHub repositories across 1,047 owners and had merged with a related VS Code task-hijacking cluster ("TaskJacker") that drops malicious `runOn: folderOpen` task files into existing repositories. Socket assesses the campaign as ongoing and expects continued new package releases as the actor rotates compromised maintainer accounts.
Each affected @joyfill package averages roughly 16,000 weekly npm downloads; exposure is limited to installs that pinned or floated onto the specific malicious beta/rc tags. No CVE has been assigned — this is a malicious-package supply-chain incident rather than a software vulnerability, and CVSS scoring is not applicable.
MITRE ATT&CK techniques used in TL-2026-1746
Collection
T1005 Data from Local System; T1074 Data Staged; T1115 Clipboard Data; T1119 Automated Collection; T1560 Archive Collected Data
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1614 System Location Discovery
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1129 Shared Modules; T1204 User Execution
Initial Access
T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship
Credential Access
T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Persistence
T1554 Compromise Host Software Binary
Resource Development
T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1587 Develop Capabilities
Impact
Affected products and versions in Two Joyfill npm Beta Releases Compromised to Deliver
- Joyfill — @joyfill/layouts (npm package)
Vulnerable versions: 0.1.2-2773.beta.0
Fixed in: 0.1.1 - Joyfill — @joyfill/components (npm package)
Vulnerable versions: 4.0.0-rc24-2773-beta.4
Fixed in: 4.0.0-rc24
Remediation for Two Joyfill npm Beta Releases Compromised to Deliver
Patches
- Upgrade to @joyfill/layouts@0.1.1
- Upgrade to @joyfill/components@4.0.0-rc24 (non-beta tag)
Immediate actions
- Remove @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 from all lockfiles, CI caches, and container images immediately
- Pin/downgrade to the clean releases: @joyfill/layouts@0.1.1 and @joyfill/components@4.0.0-rc24
- Block the identified C2 and boot infrastructure at network egress and registry proxies: 166.88.134.62, 23.27.13.43, 198.105.127.210, 23.27.202.27, 23.27.20.143, 136.0.9.8
- Treat any host that resolved a malicious beta install as compromised (not merely at-risk): rotate npm tokens, Git credentials, cloud/API keys, and password-manager master credentials; re-image if wallet extensions were present
Workarounds
- Avoid installing any beta/rc-tagged @joyfill package versions until publisher identity is re-verified
- `npm install --ignore-scripts` provides no protection — the implant executes at import time, not via install lifecycle scripts
Longer-term hardening
- Monitor developer workstation and CI-runner egress for outbound calls to Tron/Aptos/BSC RPC endpoints (api.trongrid.io, fullnode.mainnet.aptoslabs.com, bsc-dataseed.binance.org, bsc-rpc.publicnode.com) as a blockchain-dead-drop-resolver detection signal
- Enforce npm publish provenance attestation and mandatory 2FA on maintainer accounts to reduce the maintainer/build-infrastructure compromise attack surface exploited across the PolinRider campaign
- Integrity-monitor Node.js-hosted developer tools (VS Code/Cursor/Antigravity's @vscode/deviceid, Discord Desktop core module, GitHub Desktop resources/app/main.js, global npm CLI cli.js) for unauthorized modification or injection markers (/*C250617A*/, /*RS260605*/)
- Scan repositories for VS Code task files with runOn: folderOpen configurations (TaskJacker pattern) that auto-execute on repo open
Weaknesses (CWE) in Two Joyfill npm Beta Releases Compromised to Deliver
Timeline of Two Joyfill npm Beta Releases Compromised to Deliver
- Securonix first documents the DEV#POPPER campaign: North Korea-linked actors using fake job-interview lures to deliver a Python-based RAT to software developers, predating any previously recorded timeline entry for this malware family.
- Anti-dated malicious commits are later found inserted into 7span/sevenspan repositories, part of the precursor activity for the PolinRider campaign that would later be linked to this incident's malware family.
- eSentire's Threat Response Unit observes DEV#POPPER RAT and OmniStealer on an Energy, Utilities, and Waste sector customer host, delivered via the weaponized 'ShoeVista' GitHub repository.
- eSentire publishes technical analysis of DEV#POPPER RAT and OmniStealer, attributing the malware with high confidence to a North Korean state-sponsored APT and releasing the DEV#STOPPER.js deobfuscation tool.
- Partial remediation occurs on compromised PolinRider-linked repositories; malicious font files used for payload staging are removed.
- Synchronized compromise of multiple repositories under the Xpos587 GitHub account occurs at approximately 10:00 UTC, part of the expanding PolinRider campaign.
- A related cluster of seven malicious Vite-ecosystem npm packages (ViteVenom) begins publication, later found to share identical Tron/Aptos/BSC wallets and XOR decryption keys with the joyfill implant infrastructure.
- Socket publishes its PolinRider campaign report, documenting 108 compromised packages/extensions (162 malicious release artifacts) across npm, Packagist, Go modules, and Chrome, using the same Tron/Aptos/BSC blockchain-dispatch loader mechanism.
- Final ViteVenom typosquat package published, completing the seven-package cluster tied to the joyfill compromise by shared blockchain C2 infrastructure.
- Mainstream security press (The Hacker News, DevOps.com, Rescana) reports on the PolinRider campaign, noting it has touched 1,951 public GitHub repositories across 1,047 owners and merged with the TaskJacker VS Code task-hijacking cluster.
- Follow-on malicious beta tags are republished under the same implant architecture: @joyfill/layouts@0.1.2-2773.beta.1/.beta.2 and @joyfill/components@4.0.0-rc24-2773-beta.5/.beta.6.
- The Socket Threat Research Team publishes disclosure of the Joyfill npm compromise, documenting the RAT/infostealer chain and attributing it to the DEV#POPPER/PolinRider malware family via shared loader structure, header scheme, and C2 infrastructure overlap.
- @joyfill/layouts@0.1.2-2773.beta.0 is published to the npm registry containing the import-time blockchain-dispatch implant.
- @joyfill/components@4.0.0-rc24-2773-beta.4 is published to the npm registry by the same identity, containing the same implant.
- The Hacker News and multiple additional outlets (StepSecurity, gbhackers, Vulert, Mallory) publish coverage of the joyfill npm compromise specifically, with remediation guidance.
- Socket's Threat Research Team publishes full technical analysis of the joyfill implant's blockchain C2 resolution chain, worm self-propagation, and CI/sandbox-evasion logic.
Update history for TL-2026-1746
- 2026-08-13 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 65 community-related indicator(s).
- 2026-08-04 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 66 community-related indicator(s).
- 2026-08-02 — Compromised Joyfill npm Beta Packages Deliver DEV#POPPER RAT via Blockchain-Based C2: What changed No genuine escalation. The trigger report's severity (HIGH) and attribution confidence (MEDIUM) are both lower than the existing record's (CRITICAL, HIGH) and were not applied — no downgrades permitted. The malware family's doc
- 2026-07-30 — Compromised Joyfill npm Beta Packages Deliver DEV#POPPER RAT via Blockchain-Resolved Payloads: What changed No field escalations. The new report's severity (HIGH) and attribution confidence (MEDIUM) are lower than the existing record's (CRITICAL / HIGH) and are treated as downgrades — not applied. Exploitability and status unchanged
- 2026-07-30 — Two Compromised Joyfill npm Beta Packages Deploy DEV#POPPER-Linked RAT via Blockchain-Resolved Payload: What changed Severity escalated HIGH → CRITICAL: the newer report confirms the compromise continued past initial disclosure (four additional malicious beta tags republished: layouts .beta.1/.beta.2, components .beta.5/.beta.6) and documents
Sources cited for Two Joyfill npm Beta Releases Compromised to Deliver
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
- PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
- DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
- Active Exploitation Alert: North Korean PolinRider Supply Chain Attack Targets npm, Packagist, Go Modules, and Chrome Extensions
- North Korea Expands the Reach of PolinRider Supply Chain Attack Campaign
- DEV#POPPER malware profile
- PolinRider: DPRK Threat Actor Implants Malware (IOC repository)
Detection coverage for TL-2026-1746
As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1746 across Splunk SPL, Microsoft KQL and Sigma, covering 61 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1746
4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.