Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.

The list of affected packages is as follows –

@joyfill/[email protected]
@joyfill/[email protected]

The two packages “contain an import-time JavaScript implant that resolves encrypted code