SECURITY·중요도 9·2026. 07. 29.·The Hacker News
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
── KO ──────────────────
joyfill npm 패키지가 해킹되어 RAT를 배포하는 문제가 발생했습니다.
두 개의 npm 패키지인 @joyfill/layouts와 @joyfill/components가 해킹되어 원격 접근 트로이 목마(RAT)를 배포합니다. 이 패키지는 import 시점에서 암호화된 코드를 실행하는 자바스크립트 임플란트를 포함하고 있습니다. 개발자는 이 패키지를 사용하지 않는 것이 좋습니다.
── EN ──────────────────
Compromised joyfill npm packages distribute RAT when imported.
Two npm packages in the @joyfill namespace have been compromised, delivering a remote access trojan (RAT). These packages, @joyfill/layouts and @joyfill/components, contain an import-time JavaScript implant that executes encrypted code. Developers are advised to avoid using these packages.