chiprook
← Security
SecuritySeptember 21, 2026, 20:30

npm Trusted Publishing Abused to Ship GHAPPIER Loader

CloudSEK reported that attackers abused npm trusted publishing to ship a previously unreported loader, GHAPPIER, inside the legitimate package @dforge-core/dforge-mcp. Malicious releases 0.2.20 and 0.2.21 were published on September 9 with valid Sigstore provenance, and the loader fired when the MCP server was launched.

npm Trusted Publishing Abused to Ship GHAPPIER Loader
#Npm#GitHub#CloudSEK
Read next
Security

Cyberattack hits University of Munich, student data at risk

Security

TASK#STOMP Windows backdoor steals documents, Wi-Fi passwords and screenshots

Security

CVE-2026-81657 in IBM Guardium: deserialization flaw rated 9.8

Security

ShinyHunters hijacks Cl0p ransomware site, demands extortion payment