


Perceptive Security
SOC/SIEM Consultancy

Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
Published:
30 July 2026 at 20:21:18
Alert date:
31 July 2026 at 02:00:58
Source:
stepsecurity.io
Supply Chain & Dependencies, Ransomware & Malware
Malicious beta versions of two popular Joyfill npm packages, @joyfill/components and @joyfill/layouts, were found to contain an obfuscated remote access trojan (RAT) and credential stealer. The compromise represents a software supply chain attack targeting developers who install or update these packages. StepSecurity published a full analysis including indicators of compromise (IOCs) and remediation steps. The malicious code was hidden using obfuscation techniques to evade detection. Affected users are advised to audit their environments and remove the compromised versions immediately. This incident highlights ongoing risks in open-source package ecosystems like npm.
Technical details
Mitigation steps:
Affected products:
@joyfill/components
@joyfill/layouts
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
