North Korean npm developer-targeting blockchain-C2 campaign
Campaign
Summary
Hide ▲
Show ▼
An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote access and credential theft. The malicious releases execute through Node.js and resolve encrypted code with Tron, Aptos, and BNB Smart Chain transactions. The same operation is also tied to ViteVenom, showing repeated use of a blockchain-based delivery chain across multiple npm waves. The payloads can upload files, read clipboard data, and turn loaded environments into remote-control targets.
Related Happenings
SuccessKey ViteVenom ChainVeil supply-chain campaign targeting Vite developers
Campaign
H score8
First: 17.07.2026 21:54
Last: 17.07.2026 21:54
Sources 1
About this happening:
The SuccessKey-linked ViteVenom campaign is targeting Vite developers with seven malicious npm packages and a blockchain-based C2 path that delivers a RAT....
SuccessKey ViteVenom ChainVeil supply-chain campaign targeting Vite developers
CampaignAbout this happening: The SuccessKey-linked ViteVenom campaign is targeting Vite developers with seven malicious npm packages and a blockchain-based C2 path that delivers a RAT....
ViteVenom malicious npm packages delivering blockchain-backed RAT
Malware Activity
H score3
First: 17.07.2026 21:54
Last: 17.07.2026 21:54
Sources 1
About this happening:
A cluster of seven malicious npm packages has targeted the Vite frontend ecosystem, delivering a blockchain-backed RAT loader that can harvest credentials and exfiltra...
ViteVenom malicious npm packages delivering blockchain-backed RAT
Malware ActivityAbout this happening: A cluster of seven malicious npm packages has targeted the Vite frontend ecosystem, delivering a blockchain-backed RAT loader that can harvest credentials and exfiltra...
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Timeline
-
29.07.2026 07:20 2 articles · 2h ago
Compromised @joyfill npm packages deliver a DEV#POPPER-linked RAT in Node.js
Initial DisclosureBeta releases of @joyfill/[email protected] and @joyfill/[email protected] were found compromised to deliver a DEV#POPPER-associated remote access trojan when Node.js loads them, with the malicious JavaScript implant resolving encrypted payloads through Tron, Aptos, and BNB Smart Chain transactions and enabling host data collection, remote command execution, file upload, and clipboard access.
Show sources
- Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js — thehackernews.com — 29.07.2026 07:20
- Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js — thehackernews.com — 29.07.2026 07:20