


Perceptive Security
SOC/SIEM Consultancy

Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
Published:
28 July 2026 at 17:03:26
Alert date:
28 July 2026 at 18:03:14
Source:
stepsecurity.io
Supply Chain & Dependencies, Ransomware & Malware, Web Technologies
Malicious beta versions of the npm packages @joyfill/components and @joyfill/layouts were found to contain an obfuscated remote access trojan (RAT) and credential stealer. The compromise represents a supply chain attack targeting developers who install these packages. StepSecurity published a full analysis including indicators of compromise (IOCs) and remediation steps. The malicious code was hidden within what appeared to be legitimate beta releases of the Joyfill UI component library. Users of these packages are advised to audit their dependencies and remove affected versions immediately.
Technical details
Mitigation steps:
Affected products:
@joyfill/components
@joyfill/layouts
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
