Two npm Packages from joyfill Compromised with RAT Malware29. July 2026CybersecurityThe packages @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 contain a JavaScript implant that decrypts and executes malicious code on import. Share on: