Two beta npm packages in the @joyfill namespace (@joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4) were found to contain a sophisticated import-time JavaScript implant. Unlike install-hook attacks, the malware executes when the module is loaded, bypassing npm --ignore-scripts protections. The implant uses a multi-stage blockchain-backed C2 mechanism — querying Tron, Aptos, and BNB Smart Chain transactions — to retrieve an encrypted 77 KB Node.js remote-access trojan (DEV#POPPER family). A parallel detached process fetches a separate boot payload from a hardcoded IP. The final RAT can execute arbitrary JavaScript and shell commands, exfiltrate files, read clipboard data, collect host info, and persist by injecting into VS Code, Cursor, Discord Desktop, GitHub Desktop, and the global npm CLI. A Python infostealer (assessed as OmniStealer) can also be deployed, targeting browser credentials, crypto wallets, Git credentials, and more. Affected machines should be treated as fully compromised. Developers are advised to pin to pre-compromise versions and rotate all credentials accessible from the affected Node.js process.