


Perceptive Security
SOC/SIEM Consultancy

Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
Published:
29 juli 2026 om 05:53:22
Alert date:
29 juli 2026 om 06:00:56
Source:
stepsecurity.io
Supply Chain & Dependencies, Ransomware & Malware
Malicious beta versions of the Joyfill npm packages @joyfill/components and @joyfill/layouts were found to contain an obfuscated remote access trojan (RAT) and credential stealer. The compromise represents a supply chain attack targeting developers who install these packages. StepSecurity researchers performed a full analysis of the malicious code, identifying obfuscation techniques used to hide the RAT payload. The attack could expose developer environments and downstream users to credential theft and remote access by attackers. IOCs and remediation guidance were published by StepSecurity to help affected organizations respond. This incident highlights the ongoing risk of npm supply chain compromises through malicious package versions.
Technical details
Mitigation steps:
Affected products:
@joyfill/components
@joyfill/layouts
npm
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
