Elektrine lite

← Feed

@tomcat@infosec.exchange

2026-07-29 06:41 UTC

⚠️ Two compromised joyfill npm beta packages run malware as soon as Node.js imports them. No install hook needed. The implant fetches a DEV#POPPER-linked RAT through three blockchains, while a detached branch can keep running after builds or tests exit. Read the full story: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html

Replies (0)

No replies.