The Containment Era is here. →Explore

Executive Summary

In July 2026, beta versions of two npm packages within the @joyfill namespace—@joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4—were compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The malicious code executes upon package import, leveraging a multi-blockchain resolver structure involving Tron, Aptos, and BNB Smart Chain transactions to retrieve and execute encrypted payloads. This sophisticated attack vector enables the deployment of a Node.js RAT capable of file uploads, additional code retrieval, host information collection, and clipboard data access across Windows, macOS, and Linux platforms.

This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The use of blockchain-based command-and-control infrastructure highlights the evolving tactics of threat actors, emphasizing the need for enhanced vigilance and security measures in software development and deployment processes.

Why This Matters Now

The compromise of widely-used npm packages to deliver sophisticated malware like DEV#POPPER highlights the urgent need for developers and organizations to implement stringent supply chain security practices. As threat actors increasingly target open-source ecosystems, proactive measures are essential to mitigate risks associated with software dependencies.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The compromised packages are @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The CNSF would likely limit the RAT's ability to communicate with unauthorized external servers, reducing the risk of further malicious payloads being retrieved.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust Segmentation would likely constrain the RAT's access to sensitive resources, limiting its ability to escalate privileges within the environment.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-West Traffic Security would likely restrict the RAT's ability to move laterally, thereby limiting its reach to other systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud Visibility & Control would likely detect and limit unauthorized communications with external C2 servers, reducing the RAT's ability to receive further instructions.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress Security & Policy Enforcement would likely limit the RAT's ability to exfiltrate data, reducing the risk of sensitive information being transmitted to external servers.

Impact (Mitigations)

The CNSF would likely limit the overall impact by containing the attacker's activities to the initially compromised workload, reducing the blast radius.

Impact at a Glance

Affected Business Functions

  • Software Development
  • Continuous Integration/Continuous Deployment (CI/CD) Pipelines
  • Application Security
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive credentials, including API keys, database passwords, and personal identifiable information (PII) due to the remote access trojan and credential stealer deployed by the compromised packages.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict unauthorized lateral movement within the network.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities indicative of compromise.
  • Ensure Multicloud Visibility & Control to maintain oversight across diverse cloud environments and detect anomalous interactions.
  • Regularly audit and monitor third-party packages and dependencies to identify and mitigate supply chain vulnerabilities.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image