Back www.infosecurity-magazine.com Infosecurity Magazine
Attackers have abused npm trusted publishing in a supply chain attack that shipped a previously unreported loader, GHAPPIER, in a legitimate package whose malicious release carried valid provenance.
In a report published on September 20, CloudSEK said someone used the maintainer account of @dforge-core/dforge-mcp for 105 minutes on September 9. A first malicious release, 0.2.20, failed and broke installation of the package, before 0.2.21 shipped the loader and stayed the latest version for 35 minutes and 38 seconds.
The attacker could already push to the main branch. CloudSEK said it could not establish how, but suspects a developer machine infected by a malicious extension or package.
Valid Provenance, Dishonest Source
The attacker changed three lines so any push to the main branch started the release workflow, then rewrote the workflow 14 minutes later so it could publish unattended. The build ran through GitHub Actions with OIDC trusted publishing, and its attestation is still in Sigstore's public log, naming the attacker's commit.
"Provenance attests where an artefact was built, not whether its source was honest," CloudSEK said. Because the registry trusts the repository's CI identity, push access was publish access, and the release would pass npm audit signatures.
The loader was one line in a 99KB file, opening a four-stage chain that ended in a general-purpose remote shell which deleted itself from disk as it ran. It fired when the MCP server was launched rather than on install, so systems that installed 0.2.21 without starting it did not run the loader.
CloudSEK found no exploitation of GitHub, npm or any package. "Every action in this report is an authorised action taken with a stolen key," it said.
Linked to PolinRider, DPRK Unconfirmed
CloudSEK traced GHAPPIER across at least 65 public repositories, 73 infected files and 22 accounts. A second payload in another victim's repository exactly matched PolinRider , a campaign OpenSourceMalware has tracked since March 2026.
That payload read its configuration from an empty Ethereum transaction costing $0.20, leaving no domain to suspend or host to seize. Other researchers attribute PolinRider to North Korea, but CloudSEK said its one independent check did not confirm it.
CloudSEK said PolinRider's documented credential harvesting is the likeliest route into the maintainer account. It found no evidence of a successful compromise of any organization.
As of the report, no advisory had appeared in OSV, the GitHub database or from the maintainer, though every stage still responded five days after the withdrawal.
CloudSEK advised pinning the package at 0.2.22, treating any lockfile that pins 0.2.21 as an indicator in itself, and sweeping for the artifacts the chain leaves rather than the implant. It also recommended alerting on changes to a release workflow's trigger block, which here came 14 minutes before the workflow could publish.
Lookalike npm Package Hides a Multi-Stage Windows RAT News 23 June 2026
Lookalike npm Package Hides a Multi-Stage Windows RAT
Shai-Hulud-Like Worm Targets Developers via npm and AI Tools News 23 February 2026
Shai-Hulud-Like Worm Targets Developers via npm and AI Tools
Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets News 29 April 2026
Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets
FortiGuard Uncovers Deceptive Install Scripts in npm Packages News 3 October 2023
FortiGuard Uncovers Deceptive Install Scripts in npm Packages
Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets News 2 June 2026
Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets
What’s Hot on Infosecurity Magazine?
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Revolut Customers Targeted with New Wave of Phishing Attacks
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
AI Agent Carries Out Multi-Stage Data Theft Attack
Most Firms Unable to Recover Quickly from Ransomware
A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
How to Secure AI with Modern App and API Strategies
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
