Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
Attackers abused npm trusted publishing to ship the GHAPPIER loader via a legitimate package in the North Korea-linked PolinRider campaign.
Attackers compromised the npm package @dforge-core/dforge-mcp, using trusted publishing to release a malicious version (0.2.21) with valid provenance on September 9. The release contained the GHAPPIER loader, which opened a four-stage chain ending in a remote shell that deleted itself. The campaign is linked to PolinRider, attributed to North Korea, which uses cryptocurrency transactions for C2 configuration to evade infrastructure takedowns.
72