www.infosecurity-magazine.com Supply Chain Attack: GHAPPIER Loader Exploits npm Trusted Publishing
Article Content
- •GHAPPIER loader exploited npm's trusted publishing for a supply chain attack.
- •The attack involved a 105-minute compromise of a maintainer account, leading to malicious releases.
- •CloudSEK linked GHAPPIER to the PolinRider campaign, suspected to involve North Korean actors.
On September 9, 2026, an attacker compromised the maintainer account of the npm package @dforge-core/dforge-mcp for 105 minutes, releasing a malicious loader named GHAPPIER. The attack involved two versions: 0.2.20, which failed to install, and 0.2.21, which successfully shipped the loader. The malicious release exploited npm's trusted publishing mechanism, allowing the attacker to publish without valid credentials. The loader initiated a four-stage payload chain, culminating in a self-deleting remote shell. CloudSEK traced GHAPPIER across at least 65 repositories and 22 accounts, linking it to the PolinRider campaign, suspected to be associated with North Korea. No confirmed organizational compromise has been reported, but the attack highlights vulnerabilities in trusted publishing systems. Developers are advised to pin package versions and monitor release workflows.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Settra, Ghappier and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Settra Ransomware Targets Retail and Manufacturing Sectors A new variant of the Settra ransomware has emerged, specifically targeting the retail and manufacturing sectors. This ransomware employs Remote Monitoring and Management (RMM) tools and Bring Your Own Vulnerable Driver (BYOVD) techniques to infiltrate systems. The attacks have resulted in significant operational…
Ransomware Attacks Target Multiple Companies in September 2026 In September 2026, multiple ransomware groups, including Booba Project and Panzer, launched attacks on various organizations. Atlas Ocean Voyages suffered a breach where 37 GB of sensitive data was stolen, while Cerámicas Kantu S.A.C. was threatened with data release unless negotiations occurred. The attacks highlight…