


Perceptive Security
SOC/SIEM Consultancy

Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
Published:
28 juli 2026 om 19:03:26
Alert date:
28 juli 2026 om 20:03:14
Source:
stepsecurity.io
Supply Chain & Dependencies, Ransomware & Malware, Web Technologies
Malicious beta versions of the npm packages @joyfill/components and @joyfill/layouts were found to contain an obfuscated remote access trojan (RAT) and credential stealer. The compromise represents a supply chain attack targeting developers who install these packages. StepSecurity published a full analysis including indicators of compromise (IOCs) and remediation steps. The malicious code was hidden within what appeared to be legitimate beta releases of the Joyfill UI component library. Users of these packages are advised to audit their dependencies and remove affected versions immediately.
Technical details
Mitigation steps:
Affected products:
@joyfill/components
@joyfill/layouts
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
