Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
Malicious beta versions of npm packages @joyfill/components and @joyfill/layouts were published containing an obfuscated remote access trojan and credential stealer. The compromise affected developers who installed these packages during the malicious release window.
- Disclosed
- Last updated
- Blast radius
- Developers and applications using @joyfill/components and @joyfill/layouts beta versions
- Ecosystems
- Attack vectors
- Affected entities
- @joyfill/componentsMalicious beta versions
- @joyfill/layoutsMalicious beta versions
Malicious beta versions of the npm packages @joyfill/components and @joyfill/layouts were discovered to contain an obfuscated remote access trojan (RAT) and credential stealer. The compromised packages were published to the npm registry and could be installed by developers using these libraries.\n\nThe malicious code was hidden through obfuscation techniques, making it difficult to detect through standard code review. The trojan provides remote access capabilities while the credential stealer component targets sensitive authentication information from affected systems.\n\nStepSecurity identified and analyzed the compromise, providing full technical analysis, indicators of compromise (IOCs), and remediation guidance. The incident highlights the risk of supply chain attacks targeting popular development packages.
Indicators of compromise
- Packages
- @joyfill/components
- @joyfill/layouts
Remediation
- Immediately audit systems that installed @joyfill/components or @joyfill/layouts beta versions
- Remove or update to patched versions of affected packages
- Review system logs and network traffic for signs of remote access or credential theft
- Rotate any credentials that may have been exposed on affected systems
- Monitor for suspicious outbound connections from development and production environments
- Consider implementing package integrity verification and dependency scanning in CI/CD pipelines
Sources
Cite this entry
"Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 28, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/compromised-npm-packages-joyfill-components-and-joyfill-layouts-ship-an-obfuscat-1pxuye
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in sme-rko-finance-front-operations-special-payments (npm)
The npm package sme-rko-finance-front-operations-special-payments contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package employed obfuscation techniques to evade static analysis and included dual dropper paths in both index.js and lib/telemetry.js.
npmCompromised package - activecritical
Malware in bnpl-blocks-desktop-bnpl-anchor-title
Malware discovered in the npm package bnpl-blocks-desktop-bnpl-anchor-title. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malicious code in sme-rko-finance-front-operations-notifications-models (npm)
The npm package sme-rko-finance-front-operations-notifications-models contained malicious code that acts as a native-binary dropper, downloading and executing platform-specific binaries from attacker-controlled Cloudflare Workers domains and DNS fallback servers upon package require.
npmCompromised package - resolvedcritical
Malicious code in sme-rko-finance-front-operations-penalty (npm)
The npm package sme-rko-finance-front-operations-penalty contained malicious code that downloads and executes platform-specific binaries on require(). The dropper uses obfuscated string concatenation and DNS fallback channels to retrieve payloads from attacker-controlled infrastructure.
npmCompromised package