ON July 28, 2026, malicious beta versions of the npm packages @joyfill/components and @joyfill/layouts were found to contain an obfuscated remote access trojan (RAT) and credential stealer that executes upon import. The compromised packages, which are legitimate projects that were hijacked, include versions with serious vulnerabilities that allow remote access and credential theft through a multi-layered obfuscation technique.
The trojan utilizes a blockchain-based command and control method to evade detection, making interaction with its server harder to track. Users who have installed the affected versions are urged to treat their environments as compromised, remove the packages, and follow recovery steps such as credential rotation and checking for signs of intrusion. Indicators of compromise include specific package version numbers and recognizable patterns in network behavior related to command and control activities.