Skip to content
Infosecurity Magazine

Infosecurity Magazine

www.infosecurity-magazine.com September 22, 2026

Attackers have abused npm trusted publishing in a supply chain attack that shipped a previously unreported loader, GHAPPIER, in a legitimate package whose malicious release carried valid provenance.

In a report published on September 20, CloudSEK said someone used the maintainer account of @dforge-core/dforge-mcp for 105 minutes on September 9. A first malicious release, 0.2.20, failed and broke installation of the package, before 0.2.21 shipped the loader and stayed the latest version for 35 minutes and 38 seconds.

The attacker could already push to the main branch. CloudSEK said it could not establish how, but suspects a developer machine infected by a malicious extension or package.

Valid Provenance, Dishonest Source

The attacker changed three lines so any push to the main branch started the release workflow, then rewrote the workflow 14 minutes later so it could publish unattended. The build ran through GitHub Actions with OIDC trusted publishing, and its attestation is still in Sigstore's public log, naming the attacker's commit.

"Provenance attests where an artefact was built, not whether its source was honest," CloudSEK said. Because the registry trusts the repository's CI identity, push access was publish access, and the release would pass npm audit signatures.

The loader was one line in a 99KB file, opening a four-stage chain that ended in a general-purpose remote shell which deleted itself from disk as it ran. It fired when the MCP server was launched rather than on install, so systems that installed 0.2.21 without starting it did not run the loader.

CloudSEK found no exploitation of GitHub, npm or any package. "Every action in this report is an authorised action taken with a stolen key," it said.

Linked to PolinRider, DPRK Unconfirmed

CloudSEK traced GHAPPIER across at least 65 public repositories, 73 infected files and 22 accounts. A second payload in another victim's repository exactly matched PolinRider , a campaign OpenSourceMalware has tracked since March 2026.

That payload read its configuration from an empty Ethereum transaction costing $0.20, leaving no domain to suspend or host to seize. Other researchers attribute PolinRider to North Korea, but CloudSEK said its one independent check did not confirm it.

CloudSEK said PolinRider's documented credential harvesting is the likeliest route into the maintainer account. It found no evidence of a successful compromise of any organization.

As of the report, no advisory had appeared in OSV, the GitHub database or from the maintainer, though every stage still responded five days after the withdrawal.

CloudSEK advised pinning the package at 0.2.22, treating any lockfile that pins 0.2.21 as an indicator in itself, and sweeping for the artifacts the chain leaves rather than the implant. It also recommended alerting on changes to a release workflow's trigger block, which here came 14 minutes before the workflow could publish.

Lookalike npm Package Hides a Multi-Stage Windows RAT News 23 June 2026

Lookalike npm Package Hides a Multi-Stage Windows RAT

Shai-Hulud-Like Worm Targets Developers via npm and AI Tools News 23 February 2026

Shai-Hulud-Like Worm Targets Developers via npm and AI Tools

Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets News 29 April 2026

Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets

FortiGuard Uncovers Deceptive Install Scripts in npm Packages News 3 October 2023

FortiGuard Uncovers Deceptive Install Scripts in npm Packages

Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets News 2 June 2026

Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets

What’s Hot on Infosecurity Magazine?

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

Revolut Customers Targeted with New Wave of Phishing Attacks

Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing

New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

AI Agent Carries Out Multi-Stage Data Theft Attack

Most Firms Unable to Recover Quickly from Ransomware

A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

Your Security Awareness Programme Isn't Failing, It's Just Not Relevant

How to Secure AI with Modern App and API Strategies

Frontier AI: How Cyber Defenders Can Harness the Defender’s Window

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities

Campaigns (1)

Companies (1)

Countries (1)

Industries (2)

Platforms (2)

Ransomware Groups (1)