Hackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor
CloudSEK details GHAPPIER campaign compromising 65 GitHub repos to backdoor the @dforge-core/dforge-mcp npm package with cryptographically verified provenance.
The GHAPPIER operation compromised at least 65 GitHub repositories, 73 files and 22 accounts, using npm's OIDC trusted publishing via a modified GitHub Actions workflow to release a backdoored @dforge-core/dforge-mcp version 0.2.21 that carried a valid Sigstore provenance attestation. The loader activates only when the MCP server launches, running a four-stage chain that delivers a self-deleting remote shell, evading install-time and dependency scanning. A second payload exactly matches the PolinRider credential-stealing campaign, and its configuration is fetched via an empty Ethereum transaction to eliminate a blockable C2 domain.