166[.]88[.]134[.]62
Confidence: ai extracted
Source Articles 4
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
hacker-news Aug 5, 2026
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
socket-dev
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
step-security Jul 28, 2026
Joyfill npm Packages Compromised with Blockchain C2 Loader - Real-time Open Source Software Supply Chain Security
static-urls