Malicious code hidden in joyfill packages executes upon loading the CommonJS entry point—not via lifecycle hooks—and uses a multi-stage blockchain infrastructure for payload delivery that security researchers attribute to a presumed North Korean operation.
The rapidly growing Dysphoria botnet uses blockchain-based decentralized domains for C2 obfuscation and has already infected 200,000 devices through exploitation of known CVEs and weak credentials.
Dysphoria replaces centralized C2 infrastructure with blockchain name services and device relays, reducing the effectiveness of law enforcement disruptions.