Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

📡 Tech & Science

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages "contain an import-time JavaScript implant that resolves encrypted code

📖 Cet article provient d'une source externe.

🔗 Lire l'article complet sur la source →

50 mots extraits · Source originale


🔥 OFFRE PARTENAIRE

Blackview WAVE 7C, 4 Go + 128 Go, écran 6,56 pouces, Android 16, processeur quadricœur Unisoc UMS312 Tiger T310, réseau : 4G, OTG (Vitality Orange)

🔥 Blackview WAVE 7C, 4 Go + 128 Go, écran 6,56 pouces, Android 16, processeur quadricœur Unisoc UMS312 Tiger T310, réseau : 4G, OTG (Vitality Orange) - Une offre exceptionnelle à ne pas manquer ! Cliquez pour découvrir.
✅ Consultez les photos supplémentaires.

✅ Découvrez toutes les caractéristiques.

✅ Vérifiez la disponibilité actuelle.

✅ Consultez les avis des acheteurs.

Posts les plus consultés de ce blog

Better tools made Copilot code review worse. Here’s how we actually improved it.

Can AI Draw Science? A Benchmark for Evaluating Scientific Figure Generation by Text-to-Image and Multimodal Models

DOGE Used AI for Housing Policy. The Government Won’t Say How

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change

Bernie Sanders Saw This Coming

Inside the Luddite Festival Harnessing Gen Z’s Rage Against Big Tech

You Can Now Sound the Alarm on AI Behaving Badly