Find notable cyber news and cases, enriched with sources, timelines, and signals.

North Korean npm developer-targeting blockchain-C2 campaign

Campaign
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote access and credential theft. The malicious releases execute through Node.js and resolve encrypted code with Tron, Aptos, and BNB Smart Chain transactions. The same operation is also tied to ViteVenom, showing repeated use of a blockchain-based delivery chain across multiple npm waves. The payloads can upload files, read clipboard data, and turn loaded environments into remote-control targets.

Related Happenings

SuccessKey ViteVenom ChainVeil supply-chain campaign targeting Vite developers

Campaign
H score8 First: 17.07.2026 21:54 Last: 17.07.2026 21:54 Sources 1

About this happening: The SuccessKey-linked ViteVenom campaign is targeting Vite developers with seven malicious npm packages and a blockchain-based C2 path that delivers a RAT....

ViteVenom malicious npm packages delivering blockchain-backed RAT

Malware Activity
H score3 First: 17.07.2026 21:54 Last: 17.07.2026 21:54 Sources 1

About this happening: A cluster of seven malicious npm packages has targeted the Vite frontend ecosystem, delivering a blockchain-backed RAT loader that can harvest credentials and exfiltra...

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Timeline

  1. 29.07.2026 07:20 2 articles · 2h ago

    Compromised @joyfill npm packages deliver a DEV#POPPER-linked RAT in Node.js

    Initial Disclosure

    Beta releases of @joyfill/[email protected] and @joyfill/[email protected] were found compromised to deliver a DEV#POPPER-associated remote access trojan when Node.js loads them, with the malicious JavaScript implant resolving encrypted payloads through Tron, Aptos, and BNB Smart Chain transactions and enabling host data collection, remote command execution, file upload, and clipboard access.

    Show sources