malware npm

@joyfill/layouts

discovered 2026-07-28

Legitimate @joyfill/layouts package with PolinRider blockchain C2 loader injected into production JS bundles (dist/index.cjs.js and dist/index.es.js). Payload executes at require/import time. Three-layer blockchain C2: Tron address lookup -> BSC transaction data -> XOR decrypt -> eval(). Fallback spawns detached node -e child process. 30-second debounce via global['_p_t']. Campaign markers: global['!'] = '9-0135-3', global['_V'] = 'A9-0135-3'.

Threat types

c2_agent persistence

Malicious versions

  • 0.1.2-2773.beta.0 · adc4af90540d33cd…

Campaigns

Indicators

Techniques

Read the full analysis →