Incident
Published 2026-09-21
Verified 2026-09-22

CloudSEK GHAPPIER: maintainer takeover of npm @dforge-core/dforge-mcp 0.2.21 → loader across 65 GitHub repos / 22 accounts

CloudSEK (Vikas Kundu; Adversary Intelligence; datePublished 21 September 2026, also dated 20 Sep on page) documents GHAPPIER, a previously unreported loader family spanning at least 65 public GitHub repositories, 73 infected files, and 22 accounts. The investigation began when an intruder used the maintainer account of legitimate npm package @dforge-core/dforge-mcp for ~105 minutes on 9 September 2026, inserted a remote loader, and abused the project’s GitHub Actions trusted-publishing workflow so malicious version 0.2.21 shipped with valid npm provenance/Sigstore attestation; it remained the latest release for ~35 minutes before the maintainer restored clean 0.2.22. CloudSEK maps wider infrastructure and links parts of the activity beside DPRK’s PolinRider campaign. Distinct from desk cards crowdsec-tanstack-source-20260917 and npm-indexed-btree-runtime-20260920. Primary: CloudSEK blog; wire: Cyber Security News 22 Sep 2026.

Product
npm @dforge-core/dforge-mcp (compromised 0.2.21); GitHub Actions OIDC trusted publishing; GHAPPIER multi-stage loader
Versions
Malicious: @dforge-core/dforge-mcp 0.2.21 (~35 minutes as latest). Clean restore: 0.2.22. Broader: 65 repos / 73 files / 22 accounts per CloudSEK.
Exploited in Australia?
unknown
Patch to
Pin/audit @dforge-core/dforge-mcp (≥0.2.22); rotate npm and GitHub tokens for maintainers; require review gates on release workflows; hunt CloudSEK IoCs across cloned repos; treat Sigstore provenance as build-identity not code integrity

Primary: CloudSEK — GHAPPIER loader / npm trusted-publishing compromise (20–21 Sep 2026) · Vendor: CloudSEK Adversary Intelligence — GHAPPIER · Cyber Security News — GHAPPIER supply chain amplify (22 Sep 2026)

breaches cloud identity