The packages @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 contain a JavaScript implant that decrypts and executes malicious code on import.
An in-memory RAT named GoodPersonRAT is being distributed through fake LetsVPN installer packages and requires immediate vigilance regarding the origin of VPN software.
Publicly available supply-chain attack kits, commercialized RAT infrastructures, and empirically demonstrated phishing vulnerability of AI agents mark a professionalization of the threat landscape.