2026-07-29 06:41 UTC
⚠️ Two compromised joyfill npm beta packages run malware as soon as Node.js imports them. No install hook needed.
The implant fetches a DEV#POPPER-linked RAT through three blockchains, while a detached branch can keep running after builds or tests exit.
Read the full story: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
Replies (0)
No replies.