VDB

GCVE-110-OSM-2026-9199

GCVE-110-OSM-2026-9199
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 28, 2026
`@joyfill/layouts` version `0.1.2-2773.beta.0` was compromised and published on July 28, 2026 as part of the PolinRider campaign (DPRK/Lazarus Group), using the same blockchain C2 infrastructure documented by OpenSourceMalware in numerous malicious packages. Unlike previous PolinRider packages, which used disposable npm accounts or stolen GitHub identities, this is a legitimate Joyfill beta release — meaning the attacker needed to compromise an existing maintainer account to publish it. The exact mechanism (credential theft, phishing, session hijack) is not confirmed in available reporting. Malicious code appended after legitimate package code executes at module import time, delivering InvisibleFerret (also tracked as DEV#POPPER RAT). The sibling compromised package is `@joyfill/components@4.0.0-rc24-2773-beta.4`. Safe action: pin to a non-beta release and rotate all credentials on affected machines. **Execution vector** Malicious code appended after legitimate package code, executing at module `require()` time. Bypasses `npm install --ignore-scripts`. CI evasion: skips execution on hostnames `github-runner`, `buildbot`, `buildkitsandbox`, `microsoft-standard-WSL2`. **Stage 1 — blockchain resolution** Queries Tron and Aptos addresses, retrieves BSC transaction input data containing XOR-encrypted JavaScript payloads. XOR keys shared with other PolinRider-family packages: `2[gWfGj;<:-93Z^C` and `m6:tTh^D)cBz?NM]`. Tron infrastructure overlaps with OSM-documented PolinRider campaign wallets. **Stage 2 — detached execution** Spawns detached Node.js process requesting payload from `hxxp://23[.]27[.]13[.]43/$/boot` with marker header `Sec-V: A9-0135-3`. **Stage 3 — InvisibleFerret RAT (77KB, versioned 260605, also tracked as DEV#POPPER RAT)** Socket.io-based C2. Capabilities: arbitrary JavaScript/shell execution, file management and upload, clipboard extraction (Windows/macOS/Linux), host info and process listing, credential harvesting (browser profiles, wallet extensions, Git config, Chromium/Firefox data; Python infostealer component assessed as OmniStealer). Persistence: injects into VS Code, Cursor, Discord Desktop, GitHub Desktop, and global npm CLI. **Network indicators (novel to this campaign)** - `hxxp://166[.]88[.]134[.]62:443` — primary C2 - `hxxp://166[.]88[.]134[.]62:80` — alternate port - `hxxp://23[.]27[.]13[.]43` — stage 2 loader **Network indicators (shared with PolinRider campaign)** - `hxxp://198[.]105[.]127[.]210:443` - `hxxp://198[.]105[.]127[.]210:80` - `hxxp://23[.]27[.]202[.]27:443` - `hxxp://23[.]27[.]202[.]27:27017` **Blockchain indicators (Tron, shared with PolinRider campaign)** - `TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP` - `TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG` - `TA48dct6rFW8BXsiLAtjFaVFoSuryMjD3v`

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@joyfill/layouts0.1.2-2773.beta.0 (affected)

References

vendor

Browse GCVE Records

75,823 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›