Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
Malicious beta versions of npm packages @joyfill/components and @joyfill/layouts were published containing an obfuscated remote access trojan and credential stealer. The compromise affected developers who installed these packages during the malicious release window.
- Disclosed
- Last updated
- Blast radius
- Developers and applications using @joyfill/components and @joyfill/layouts beta versions
- Ecosystems
- Attack vectors
- Affected entities
- @joyfill/componentsMalicious beta versions
- @joyfill/layoutsMalicious beta versions
Malicious beta versions of the npm packages @joyfill/components and @joyfill/layouts were discovered to contain an obfuscated remote access trojan (RAT) and credential stealer. The compromised packages were published to the npm registry and could be installed by developers using these libraries.\n\nThe malicious code was hidden through obfuscation techniques, making it difficult to detect through standard code review. The trojan provides remote access capabilities while the credential stealer component targets sensitive authentication information from affected systems.\n\nStepSecurity identified and analyzed the compromise, providing full technical analysis, indicators of compromise (IOCs), and remediation guidance. The incident highlights the risk of supply chain attacks targeting popular development packages.
Indicators of compromise
- Packages
- @joyfill/components
- @joyfill/layouts
Remediation
- Immediately audit systems that installed @joyfill/components or @joyfill/layouts beta versions
- Remove or update to patched versions of affected packages
- Review system logs and network traffic for signs of remote access or credential theft
- Rotate any credentials that may have been exposed on affected systems
- Monitor for suspicious outbound connections from development and production environments
- Consider implementing package integrity verification and dependency scanning in CI/CD pipelines
Sources
Cite this entry
"Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 28, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/compromised-npm-packages-joyfill-components-and-joyfill-layouts-ship-an-obfuscat-1pxuye
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in @omniwatch-wick/cli
Malware discovered in the npm package @omniwatch-wick/cli. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in chain-manager
Malware discovered in the npm package chain-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malicious code in toll_free (npm)
The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malicious code in blots (npm)
The npm package 'blots' version 2.1.0 was identified by the OpenSSF Package Analysis project as containing malicious code that executes commands associated with malicious behavior. The package has been flagged in the OpenSSF malicious packages database.
npmCompromised package