NPM · JULY 2026 · EARLY WARNING

Joyfill npm Packages @joyfill/components and @joyfill/layouts Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity: HIGH

Malicious beta versions of the Joyfill npm packages @joyfill/components and @joyfill/layouts appear to hide an obfuscated remote access trojan and credential stealer. Users of these beta versions are advised to take immediate action.

What happened

Reportedly, beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The affected packages are @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4. The malicious code runs when Node.js loads the CommonJS package entry point, resolving encrypted code through Tron, Aptos, and BNB Smart Chain transactions.

The implant consists of two parallel sequences of actions: an in-process branch that leads to a recovered 77 KB JavaScript payload with similarities to the DEV#POPPER malware family, and a secondary branch that launches a detached Node.js process, requests a separate boot payload from a remote server, decrypts the response, and evaluates it. This behavior has been linked to a threat cluster tracked as PolinRider.

If your repositories, CI/CD pipelines, or developer machines have installed any 2773 prerelease of @joyfill/components or @joyfill/layouts, it is recommended to treat those environments as compromised. Remove the affected versions, pin to a known good release published before July 28, 2026, and consider rotating credentials as a precautionary measure. For more details, consult the primary sources.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If @joyfill/components is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats