Skip to content
Supply Chain Attack: GHAPPIER Loader Exploits npm Trusted Publishing

Supply Chain Attack: GHAPPIER Loader Exploits npm Trusted Publishing

First seen 22 Sep 2026, 13:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 14:26 UTC
  • GHAPPIER loader exploited npm's trusted publishing for a supply chain attack.
  • The attack involved a 105-minute compromise of a maintainer account, leading to malicious releases.
  • CloudSEK linked GHAPPIER to the PolinRider campaign, suspected to involve North Korean actors.

On September 9, 2026, an attacker compromised the maintainer account of the npm package @dforge-core/dforge-mcp for 105 minutes, releasing a malicious loader named GHAPPIER. The attack involved two versions: 0.2.20, which failed to install, and 0.2.21, which successfully shipped the loader. The malicious release exploited npm's trusted publishing mechanism, allowing the attacker to publish without valid credentials. The loader initiated a four-stage payload chain, culminating in a self-deleting remote shell. CloudSEK traced GHAPPIER across at least 65 repositories and 22 accounts, linking it to the PolinRider campaign, suspected to be associated with North Korea. No confirmed organizational compromise has been reported, but the attack highlights vulnerabilities in trusted publishing systems. Developers are advised to pin package versions and monitor release workflows.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-09
Attacker compromised npm maintainer account
The maintainer account for @dforge-core/dforge-mcp was accessed for 105 minutes, allowing malicious changes.
Cloudsek
2026-09-09
Malicious versions 0.2.20 and 0.2.21 released
Version 0.2.20 failed to install, while 0.2.21 successfully shipped the GHAPPIER loader for 35 minutes.
Infosecurity Magazine
2026-09-20
CloudSEK reports on GHAPPIER
CloudSEK published findings detailing the attack, its methods, and links to the PolinRider campaign.
Cloudsek
2026-09-22
Infosecurity Magazine updates on the attack
Infosecurity Magazine published an article summarizing the attack and its implications for npm users.
Infosecurity Magazine

More articles in this cluster (3)

Following this threat?

Track Settra, Ghappier and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed