Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials

A fresh supply chain scare hit software teams after attackers slipped malware into trusted open source libraries. On July 28, 2026, malicious beta builds of two Joyfill packages appeared on the npm registry. The libraries, @joyfill/components and @joyfill/layouts, are used for forms and layout work in many web apps. Anyone who imported those beta builds […]

This article has been indexed from Cyber Security News

Read the original article: