Back Msspalert New malware loader GHAPPIER abused npm trusted publishing | brief
Magnifying glass over code on dark screen symbolizing cybersecurity investigation and digital forensics, with emphasis on evidence analysis and threat detection.
Attackers have successfully exploited a supply chain attack by abusing npm's trusted publishing mechanism to distribute a previously unknown malware loader called GHAPPIER within a legitimate package, following a report by Infosecurity Magazine.
The attack involved compromising the maintainer account for the @dforge-core/dforge-mcp package on npm. An attacker gained control for approximately 105 minutes, during which they released version 0.2.20, which failed to install, followed by version 0.2.21 that successfully shipped the GHAPPIER loader. This malicious release utilized GitHub Actions with OIDC trusted publishing, generating an attestation that appeared legitimate but masked the dishonest source. The loader, a single line within a larger file, initiated a four-stage payload chain culminating in a self-deleting remote shell.
CloudSEK traced GHAPPIER across numerous repositories and files, noting similarities to the PolinRider campaign, which has been linked by some researchers to North Korea, though this remains unconfirmed. The attack vector is believed to be the theft of maintainer credentials, potentially through malicious browser extensions or packages. No organizational compromise was confirmed, but CloudSEK advises developers to pin package versions and monitor changes to release workflows to prevent similar incidents.
Source: Infosecurity Magazine
MSSP Alert Team September 18, 2026
MSSP Alert Team September 15, 2026
MSSP Alert Team September 11, 2026
You can skip this ad in 5 seconds
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
