TI Mindmap HUB
Threat Intelligence Report

Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

๐Ÿ“… July 30, 2026 ๐Ÿ“ฐ www.stepsecurity.io ๐Ÿ” 0 CVE(s) referenced

Malicious beta versions of the @joyfill/components and @joyfill/layouts npm packages delivered a highly obfuscated, multi-stage remote access trojan and credential stealer that activates on import, hijacks developer environments, and spreads via supply chain, making immediate remediation and credential rotation critical for affected users.

unclassified

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle