Joyfill A.I CyberSecurity Scoring
Joyfill
Company Information
Website:https://joyfill.io
Employees number:13
Number of followers:126
NAICS:5112
Industry Type:Software Development
Homepage:joyfill.io
Joyfill Risk Score (AI oriented)
Between 700 and 749
JoyfillSoftware Development
Updated:
29/07/2026
29/07/2026
734/1000
Moderate
Ba
Joyfill Global Score (TPRM)
xxxx
JoyfillSoftware Development
Score locked

JoyfillModerate
Current Score
734Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
734
JULY 2026
752
Cyber Attack
28 Jul 2026 • Joyfill
Joyfill: Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials
Malicious npm Packages Target Developer Workstations in Supply Chain Attack
734
CRITICAL-18
JOY1785342538
Malicious npm Packages Target Developer Workstations in Supply Chain Attack
On July 28, 2026, attackers compromised two widely used open-source npm packages @joyfill/components and @joyfill/layouts by publishing malicious beta versions to the npm registry. The affected packages, used for forms and layout development in web applications, contained hidden malware that executed upon import, bypassing traditional install scripts.
Security firm StepSecurity uncovered the campaign after automated scans flagged a critical build of the layouts package. Analysis revealed that the malware, embedded directly in the package tarballs (not the source code), established a remote control channel to steal developer secrets, including browser data, Git tokens, npm credentials, and wallet keys. The attack leveraged blockchain-based command-and-control (C2) resolution, dynamically fetching server addresses to evade detection.
The malware exhibited worm-like behavior, injecting itself into popular developer tools such as VS Code, Cursor, Discord, GitHub Desktop, and the npm CLI. This persistence mechanism allowed the threat to survive restarts, with every subsequent npm command potentially reloading the malicious payload. Over 2,773 beta releases were published within hours, all tied to the same campaign tag (A9-0135-3).
The attack chain involved five stages:
1. Initial execution upon package import, setting a campaign tag and exposing Node.js features.
2. C2 resolution via blockchain endpoints (e.g., api.trongrid.io, fullnode.mainnet.aptoslabs.com) to locate active servers.
3. Socket.IO connection for remote control, enabling file theft, script execution, and clipboard monitoring.
4. Self-propagation into developer tools, ensuring persistence.
5. Credential harvesting via a Python-based stealer targeting browsers, password managers, and keychains.
Indicators of compromise (IoCs) include the malicious package versions (e.g., @joyfill/[email protected]), C2 IP addresses (166.88.134.62, 23.27.13.43), and injection markers in developer tool files (C250617A, RS260605). Organizations that imported these versions should remove the packages, reinstall from clean lockfiles, and rotate all exposed credentials.
The incident reflects a broader trend of open-source supply chain attacks, where legitimate projects are hijacked to distribute malware at scale. Similar campaigns have exploited stolen tokens to access cloud platforms and code repositories, underscoring the risks of import-time execution in dependency management.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
752
MAY 2026
752
APRIL 2026
752
MARCH 2026
752
FEBRUARY 2026
752
JANUARY 2026
752
DECEMBER 2025
752
NOVEMBER 2025
752
OCTOBER 2025
752
SEPTEMBER 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Joyfill ??
What was Joyfill's A.I Rankiteo Cyber Score in July 2026 ??
What was Joyfill's A.I Rankiteo Cyber Score in June 2026 ??
What was Joyfill's A.I Rankiteo Cyber Score in May 2026 ??
What was Joyfill's A.I Rankiteo Cyber Score in April 2026 ??
What was Joyfill's A.I Rankiteo Cyber Score in March 2026 ??
What was Joyfill's A.I Rankiteo Cyber Score in February 2026 ??
What was Joyfill's A.I Rankiteo Cyber Score in January 2026 ??
What was Joyfill's A.I Rankiteo Cyber Score in December 2025 ??
What was Joyfill's A.I Rankiteo Cyber Score in November 2025 ??
What was Joyfill's A.I Rankiteo Cyber Score in October 2025 ??
What was Joyfill's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Joyfill's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Joyfill ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Joyfill's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?