Malware, Third-party code, DevSecOps, Threat Intelligence

New malware loader GHAPPIER abused npm trusted publishing

Magnifying glass over code on dark screen symbolizing cybersecurity investigation and digital forensics, with emphasis on evidence analysis and threat detection.

Attackers have successfully exploited a supply chain attack by abusing npm's trusted publishing mechanism to distribute a previously unknown malware loader called GHAPPIER within a legitimate package, following a report by Infosecurity Magazine.

The attack involved compromising the maintainer account for the @dforge-core/dforge-mcp package on npm. An attacker gained control for approximately 105 minutes, during which they released version 0.2.20, which failed to install, followed by version 0.2.21 that successfully shipped the GHAPPIER loader. This malicious release utilized GitHub Actions with OIDC trusted publishing, generating an attestation that appeared legitimate but masked the dishonest source. The loader, a single line within a larger file, initiated a four-stage payload chain culminating in a self-deleting remote shell.

CloudSEK traced GHAPPIER across numerous repositories and files, noting similarities to the PolinRider campaign, which has been linked by some researchers to North Korea, though this remains unconfirmed. The attack vector is believed to be the theft of maintainer credentials, potentially through malicious browser extensions or packages. No organizational compromise was confirmed, but CloudSEK advises developers to pin package versions and monitor changes to release workflows to prevent similar incidents.

Source: Infosecurity Magazine

You can skip this ad in 5 seconds