In summary: Malicious code hidden in joyfill packages executes upon loading the CommonJS entry point—not via lifecycle hooks—and uses a multi-stage blockchain infrastructure for payload delivery that security researchers attribute to a presumed North Korean operation.
Beta versions of the npm packages @joyfill/layouts (0.1.2-2773.beta.0) and @joyfill/components (4.0.0-rc24-2773-beta.4) contain malicious code that executes during Node.js module initialization, thereby circumventing standard npm protection measures.
The security company Socket has analyzed two compromised npm package versions from the @joyfill namespace. The embedded JavaScript malicious code becomes active at import time and loads encrypted code via blockchain transactions—across the Tron, Aptos, and BNB Smart Chain networks. This renders standard defensive measures ineffective, such as installation with the –ignore-scripts option, because the code is triggered not via npm lifecycle hooks but directly during CommonJS loading of the package.
Socket attributes the infrastructure to the threat cluster PolinRider, which is said to be linked to the “Contagious Interview” campaign. In April, Checkmarx and OpenSourceMalware documented a similar operation called ViteVenom in the Vite frontend ecosystem, which utilized the same blockchain infrastructure. Both campaigns suggest to security researchers a shared, presumed North Korean operation. The malicious code branches into two parallel delivery paths: One branch running within the same process loads a JavaScript payload of approximately 77 KB that resembles the DEV#POPPER malware family. A second, independent Node.js process loads additional payloads from 23.27.13.43 and can remain active even after builds or CLI commands complete.
The final malware (internally called “clientCode”) functions as a full-featured Node.js remote access trojan with extensive capabilities: it can upload files to a configured server, load additional JavaScript code, gather system information, and exfiltrate clipboard data (on Windows via PowerShell, macOS via pbpaste, Linux via xclip or xsel). On hostnames such as github-runner, buildbot, buildkitsandbox, and microsoft-standard-WSL2, which typically indicate development and test environments, the malware deliberately refrains from execution. An associated Python info stealer is based on OmniStealer (described in April by eSentire) and can steal credentials from Windows Credential Manager, Linux Secret Service, data from Chromium and Firefox browsers, wallet and password manager extensions, Git access credentials, and configurations and logs from GitHub CLI, GitHub Desktop, and Visual Studio Code.
Socket identified both malicious versions as published by the same npm identity, using Node.js 18.20.0 and npm 10.5.0. The vector of compromise—whether developer workstation, source code repository, CI environment, or stolen publishing credentials—remains unclear.
Source: www.it-daily.net · Published 31 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.