Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

Malicious beta versions of npm packages @joyfill/components and @joyfill/layouts were published containing an obfuscated remote access trojan and credential stealer. The compromise affected developers who installed these packages during the malicious release window.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Developers and applications using @joyfill/components and @joyfill/layouts beta versions
Ecosystems
Attack vectors
Affected entities
  • @joyfill/componentsMalicious beta versions
  • @joyfill/layoutsMalicious beta versions

Malicious beta versions of the npm packages @joyfill/components and @joyfill/layouts were discovered to contain an obfuscated remote access trojan (RAT) and credential stealer. The compromised packages were published to the npm registry and could be installed by developers using these libraries.\n\nThe malicious code was hidden through obfuscation techniques, making it difficult to detect through standard code review. The trojan provides remote access capabilities while the credential stealer component targets sensitive authentication information from affected systems.\n\nStepSecurity identified and analyzed the compromise, providing full technical analysis, indicators of compromise (IOCs), and remediation guidance. The incident highlights the risk of supply chain attacks targeting popular development packages.

Indicators of compromise

Packages
  • @joyfill/components
  • @joyfill/layouts

Remediation

  • Immediately audit systems that installed @joyfill/components or @joyfill/layouts beta versions
  • Remove or update to patched versions of affected packages
  • Review system logs and network traffic for signs of remote access or credential theft
  • Rotate any credentials that may have been exposed on affected systems
  • Monitor for suspicious outbound connections from development and production environments
  • Consider implementing package integrity verification and dependency scanning in CI/CD pipelines

Sources

  1. Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan · StepSecurity

Cite this entry

"Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 28, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/compromised-npm-packages-joyfill-components-and-joyfill-layouts-ship-an-obfuscat-1pxuye

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in @omniwatch-wick/cli

    Malware discovered in the npm package @omniwatch-wick/cli. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2. activecritical

    Malware in chain-manager

    Malware discovered in the npm package chain-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  3. containedcritical

    Malicious code in toll_free (npm)

    The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  4. containedcritical

    Malicious code in blots (npm)

    The npm package 'blots' version 2.1.0 was identified by the OpenSSF Package Analysis project as containing malicious code that executes commands associated with malicious behavior. The package has been flagged in the OpenSSF malicious packages database.

    npmCompromised package