malware npm

@joyfill/components

discovered 2026-07-28

Delivery vehicle for the PolinRider blockchain C2 loader. Chains to the malicious @joyfill/layouts@0.1.2-2773.beta.0 via npm dependency, causing the layouts payload to execute when components is installed and imported.

Threat types

c2_agent

Malicious versions

  • 4.0.0-rc24-2773-beta.4 · bcc93dc55bc7daed…

Campaigns

Techniques

Read the full analysis →