GHAPPIER Supply Chain Attack Backdoors npm Package @dforge-core/dforge-mcp via Trusted Publishing
Attackers compromised a maintainer account and abused npm's OIDC trusted publishing to release a backdoored @dforge-core/dforge-mcp 0.2.21 with valid provenance, delivering the four-stage GHAPPIER loader tied to the PolinRider credential-stealing campaign…
Research detailed by CloudSEK and reported by GBHackers and Cyber Security News tracks the GHAPPIER operation, in which attackers compromised at least 65 GitHub repositories, 73 files and 22 accounts and modified a GitHub Actions workflow to abuse npm's OIDC trusted publishing. On September 9, 2026, an intruder held the @dforge-core/dforge-mcp maintainer account for 105 minutes and published version 0.2.21 carrying a valid Sigstore provenance attestation; the poisoned release stayed live for 35 minutes. The package contained the GHAPPIER loader, which activates only when the MCP server launches — evading install-time and dependency scanning — and runs a four-stage chain ending in a remote shell that deletes itself from disk; stages were still responding five days later. A second payload exactly matches the PolinRider credential-stealing campaign, tracked since March 2026, which harvests cached Git credentials and reads its C2 configuration from an empty Ethereum transaction, eliminating any blockable C2 domain. Infosecurity Magazine attributes PolinRider to North Korea; the other two reports state the PolinRider link without the state attribution. No downstream organizational compromise was confirmed; users are advised to pin version 0.2.22 and audit for 0.2.21.
- Malicious release: @dforge-core/dforge-mcp version 0.2.21, published September 9, 2026, via npm OIDC trusted publishing from a compromised maintainer repo, carrying a valid Sigstore provenance attestation.
- Scale per CloudSEK: 65 GitHub repositories, 73 infected files, and 22 accounts compromised.
- The intruder controlled the maintainer account for 105 minutes; the poisoned release remained live for 35 minutes.
- The GHAPPIER loader executes only on MCP server launch, running a four-stage chain that delivers a self-deleting remote shell, evading install-time and dependency scanning; stages still responded five days later.
- A second payload exactly matches the PolinRider credential stealer, tracked since March 2026; it harvests cached Git credentials and fetches C2 configuration from an empty Ethereum transaction, removing any blockable C2 domain.
- North Korea attribution for PolinRider appears in only one of the three reports (Infosecurity Magazine); the others report the PolinRider link without state attribution.
- No downstream organizational compromise was confirmed; recommended remediation is pinning version 0.2.22 and auditing for 0.2.21.
Coverage timelineoldest first · each row is one article
- · 5d agoAttackers Abuse npm Trusted Publishing in GHAPPIER Campaign
Infosecurity Magazine· 72
Attackers abused npm trusted publishing to ship the GHAPPIER loader via a legitimate package in the North Korea-linked PolinRider campaign.
- · 4d agoHackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor
GBHackers· 65
CloudSEK details GHAPPIER campaign compromising 65 GitHub repos to backdoor the @dforge-core/dforge-mcp npm package with cryptographically verified provenance.
- · 4d agoGHAPPIER Supply Chain Attack Compromises 65 GitHub Repositories and Poisons npm Package
Cyber Security News· 55