Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Overview
Two beta versions of npm packages from the @joyfill namespace have been compromised to include a remote access trojan (RAT) linked to the DEV#POPPER malware family. The affected packages are @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4. When these packages are imported into a Node.js environment, they execute an implant that runs encrypted malicious code. This incident poses a significant risk to developers who might unknowingly use these compromised packages in their projects. Users are advised to avoid these specific versions and monitor for any unusual activity in their systems.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: @joyfill/layouts@0.1.2-2773.beta.0, @joyfill/components@4.0.0-rc24-2773-beta.4
- Action Required: Avoid using the affected package versions and monitor systems for unusual activity.
- Timeline: Newly disclosed
Original Article Summary
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages "contain an import-time JavaScript implant that resolves encrypted code
Impact
@joyfill/layouts@0.1.2-2773.beta.0, @joyfill/components@4.0.0-rc24-2773-beta.4
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Avoid using the affected package versions and monitor systems for unusual activity.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware, Trojan.