# Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

> Beta releases of two npm packages in the @joyfill namespace (@joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4), published July 28, 2026 by the same npm identity, contain an import-time JavaScript implant that resolves an encrypted 77KB Node.js RAT via Tron/Aptos/BNB Smart Chain transactions (no traditional C2 for stage-1 delivery), then stages an 82KB Python infostealer targeting browser data, Git credentials, and 200+ wallet/password-manager extensions.

- **Published:** 2026-07-28T00:00:00Z
- **Last reviewed:** 2026-08-13T10:34:03Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1746
- **ID:** TL-2026-1746
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** Contagious Interview - G1052 (North Korea)
- **Detections:** 9 · **IOCs:** 61 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-07-28, the Socket Threat Research Team identified two malicious beta releases in the @joyfill npm namespace: @joyfill/layouts@0.1.2-2773.beta.0 (published 10:54:57 UTC) and @joyfill/components@4.0.0-rc24-2773-beta.4 (published 11:03:59 UTC), both published by the same npm identity using Node.js 18.20.0 and npm 10.5.0. The malicious code was present in the published bundle at publish time rather than injected via a compromised install script, indicating either maintainer credential compromise or compromised build/CI infrastructure upstream of `npm publish`.

The implant executes at import time (no install-script trigger, so `npm install --ignore-scripts` provides no protection) and runs a three-stage architecture. Stage 0 (Bootstrap) forks both an in-process path and a detached `child_process.spawn({ detached: true })` path. Stage 1 (Blockchain Dispatch) resolves encrypted payload material with no reliance on conventional DNS/HTTP C2 infrastructure: it reads Tron account transactions (`TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP` in-process, `TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG` detached), falls back to Aptos account transactions, and to BNB Smart Chain transactions retrieved via `eth_getTransactionByHash`, decoding and XOR-decrypting the transaction payload with path-specific keys. This blockchain-as-dead-drop-resolver pattern makes takedown far harder than IP/domain blocklisting, since the resolver infrastructure is a public, permissionless ledger. Stage 2 delivers the 77KB Node.js RAT (SHA-256 26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18) via a second-tier blockchain resolution. A parallel detached "boot downloader" process independently requests `23.27.13.43/$/boot` with a custom `Sec-V: A9-0135-3` header and decrypts the response with the key `ThZG+0jfXE6VAGOJ`.

The delivered RAT exposes a socket.io-style command vocabulary (`ss_eval`/`ss_eval64` for JS/base64 execution, `ss_upf`/`ss_upd` for file transfer, `ss_dir` for directory enumeration, `ss_fcd` for file modification/traversal), reads the OS clipboard (PowerShell on Windows, `pbpaste`/`xclip`/`xsel` on Unix), enumerates Windows processes, and calls `ip-api.com` for public-IP fingerprinting. It persists by patching Node.js-hosted developer tools directly: `@vscode/deviceid` (covering VS Code, Cursor, and Antigravity), the Discord Desktop core module, GitHub Desktop's `resources/app/main.js`, and the global npm CLI at `node_modules/npm/lib/cli.js` — guaranteeing re-execution on next launch of any of those apps. Injected code carries recognizable markers (`/*C250617A*/`, `/*RS260605*/`).

The `/$/boot` response delivers a second payload: an 82KB Python infostealer (SHA-256 36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c) that harvests Windows Credential Manager and Linux Secret Service entries, Chromium/Firefox storage, wallet-manager and password-manager browser extensions, Git credentials and GitHub CLI config, and VS Code storage — staging everything as an AES-encrypted ZIP (password `,./,./,./`) under `%USERPROFILE%\.npm` (Windows) or `/tmp/.npm` (Linux/macOS) before optional Telegram-bot exfiltration. Socket assesses "medium likelihood" this is an iteration of the OmniStealer family.

Attribution ties this incident to the DEV#POPPER malware family via shared structural fingerprints: the PolinRider-family multi-chain loader structure (`rmcej%otb%` marker, shared global-naming conventions), the identical `Sec-V` header scheme and `/$/boot` endpoint design, the `ss_*` socket.io command vocabulary, and matching XOR key derivation. DEV#POPPER was first documented by eSentire's Threat Response Unit (TRU) in a February 2026 incident on an Energy/Utilities/Waste customer host, where a victim cloned a weaponized GitHub repository ("ShoeVista", disguised as an e-commerce platform), launched its frontend, and triggered a Node.js backdoor hidden by whitespace padding in `frontend/tailwind.config.js`. eSentire attributes DEV#POPPER with high confidence to a North Korean state-sponsored APT, noting the RAT primarily targets macOS (also Windows/Linux) and is used to steal cryptocurrency wallets and developer secrets (source-code credentials, API keys, cloud tokens). Network overlap between the Joyfill incident's C2 set (166.88.134.62, 23.27.13.43, 198.105.127.210, 23.27.202.27) and eSentire's documented DEV#POPPER infrastructure (23.27.20.143 and 23.27.202.27 both on ASN 149440, Evoxt Sdn. Bhd.; plus 136.0.9.8) corroborates shared operator infrastructure.

The delivery mechanism also matches the broader PolinRider campaign that Socket disclosed on 2026-07-01: a North Korea-linked (Contagious Interview / Famous Chollima cluster) operation that has compromised 108 unique packages/extensions (162 malicious release artifacts) across npm (19), Packagist (10), Go modules (61), and Chrome Web Store (1), via maintainer/build-infrastructure compromise on accounts such as `Xpos587` (GitHub) and the `7span`/`sevenspan` namespace (GitHub/Packagist). PolinRider's loader reaches TRON, Aptos, and BNB Smart Chain RPC infrastructure to retrieve and XOR-decrypt second-stage material before executing it with `eval()`, and has been observed delivering both DEV#POPPER and OmniStealer — the loader design means it is capable of delivering additional payload families. As of a 2026-07-04 report, PolinRider-linked activity had touched 1,951 public GitHub repositories across 1,047 owners and had merged with a related VS Code task-hijacking cluster ("TaskJacker") that drops malicious `runOn: folderOpen` task files into existing repositories. Socket assesses the campaign as ongoing and expects continued new package releases as the actor rotates compromised maintainer accounts.

Each affected @joyfill package averages roughly 16,000 weekly npm downloads; exposure is limited to installs that pinned or floated onto the specific malicious beta/rc tags. No CVE has been assigned — this is a malicious-package supply-chain incident rather than a software vulnerability, and CVSS scoring is not applicable.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1195 Supply Chain Compromise
- T1078 Valid Accounts
- T1204 User Execution
- T1129 Shared Modules
- T1059 Command and Scripting Interpreter
- T1554 Compromise Host Software Binary
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1622 Debugger Evasion
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1057 Process Discovery
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1115 Clipboard Data
- T1005 Data from Local System
- T1119 Automated Collection
- T1102 Web Service
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1573 Encrypted Channel
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft
- T1497 Virtualization/Sandbox Evasion
- T1586 Compromise Accounts
- T1199 Trusted Relationship
- T1106 Native API
- T1614 System Location Discovery
- T1074 Data Staged
- T1571 Non-Standard Port
- T1008 Fallback Channels
- T1070 Indicator Removal
- T1560 Archive Collected Data

## Sources

- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://socket.dev/blog/joyfill-npm-beta-releases-compromised)
- [PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems](https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands)
- [DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')](https://www.esentire.com/blog/north-korean-apt-malware-analysis-dev-popper-rat-and-omnistealer-everyday-im-shufflin)
- [North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign](https://thehackernews.com/2026/07/north-korean-hackers-publish-108.html)
- [Active Exploitation Alert: North Korean PolinRider Supply Chain Attack Targets npm, Packagist, Go Modules, and Chrome Extensions](https://www.rescana.com/post/active-exploitation-alert-north-korean-polinrider-supply-chain-attack-targets-npm-packagist-go-modules-and-chrome-extens)
- [North Korea Expands the Reach of PolinRider Supply Chain Attack Campaign](https://devops.com/north-korea-expands-the-reach-of-polinrider-supply-chain-attack-campaign/)
- [DEV#POPPER malware profile](https://www.mallory.ai/malware/019cdd4c-2922-7934-84fc-eb5fbf2d59e1)
- [PolinRider: DPRK Threat Actor Implants Malware (IOC repository)](https://github.com/OpenSourceMalware/PolinRider)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1746
