npm Trusted Publishing Abused to Ship GHAPPIER Loader
CloudSEK reported that attackers abused npm trusted publishing to ship a previously unreported loader, GHAPPIER, inside the legitimate package @dforge-core/dforge-mcp. Malicious releases 0.2.20 and 0.2.21 were published on September 9 with valid Sigstore provenance, and the loader fired when the MCP server was launched.
- Malicious version 0.2.21 stayed the latest release for 35 minutes 38 seconds
- The loader was one line in a 99KB file and fired on MCP server launch
- GHAPPIER was traced across 65 repositories, 73 files and 22 accounts
- A second payload matched PolinRider and read config from a $0.20 Ethereum transaction
Read next
Security