CloudSEK GHAPPIER: maintainer takeover of npm @dforge-core/dforge-mcp 0.2.21 → loader across 65 GitHub repos / 22 accounts
CloudSEK (Vikas Kundu; Adversary Intelligence; datePublished 21 September 2026, also dated 20 Sep on page) documents GHAPPIER, a previously unreported loader family spanning at least 65 public GitHub repositories, 73 infected files, and 22 accounts. The investigation began when an intruder used the maintainer account of legitimate npm package @dforge-core/dforge-mcp for ~105 minutes on 9 September 2026, inserted a remote loader, and abused the project’s GitHub Actions trusted-publishing workflow so malicious version 0.2.21 shipped with valid npm provenance/Sigstore attestation; it remained the latest release for ~35 minutes before the maintainer restored clean 0.2.22. CloudSEK maps wider infrastructure and links parts of the activity beside DPRK’s PolinRider campaign. Distinct from desk cards crowdsec-tanstack-source-20260917 and npm-indexed-btree-runtime-20260920. Primary: CloudSEK blog; wire: Cyber Security News 22 Sep 2026.
- Product
- npm @dforge-core/dforge-mcp (compromised 0.2.21); GitHub Actions OIDC trusted publishing; GHAPPIER multi-stage loader
- Versions
- Malicious: @dforge-core/dforge-mcp 0.2.21 (~35 minutes as latest). Clean restore: 0.2.22. Broader: 65 repos / 73 files / 22 accounts per CloudSEK.
- Exploited in Australia?
- unknown
- Patch to
- Pin/audit @dforge-core/dforge-mcp (≥0.2.22); rotate npm and GitHub tokens for maintainers; require review gates on release workflows; hunt CloudSEK IoCs across cloned repos; treat Sigstore provenance as build-identity not code integrity
Primary: CloudSEK — GHAPPIER loader / npm trusted-publishing compromise (20–21 Sep 2026) · Vendor: CloudSEK Adversary Intelligence — GHAPPIER · Cyber Security News — GHAPPIER supply chain amplify (22 Sep 2026)
