Find notable cyber news and cases, enriched with sources, timelines, and signals.

GHAPPIER loader in @dforge-core/dforge-mcp malicious npm release

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

A malicious npm release of @dforge-core/dforge-mcp shipped the GHAPPIER loader with valid provenance, affecting 65 public repositories, 73 infected files, and 22 accounts. The release used GitHub Actions and OIDC trusted publishing, allowing the package to pass provenance checks while still carrying malicious code. The loader activated when the MCP server launched and opened a staged chain that ended in a self-deleting remote shell.

Related Happenings

ViteVenom malicious npm packages delivering blockchain-backed RAT

Malware Activity
H score3 First: 17.07.2026 21:54 Last: 17.07.2026 21:54 Sources 1

About this happening: A cluster of seven malicious npm packages has targeted the Vite frontend ecosystem, delivering a blockchain-backed RAT loader that can harvest credentials and exfiltra...

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

AsyncAPI repositories and npm publishing workflow hit by network compromise

Incident
H score27 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

@Injectivelabs/[email protected] wallet-stealing package

Malware Activity
H score30 First: 10.07.2026 20:29 Last: 10.07.2026 20:29 Sources 1

About this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...

Timeline

  1. 21.09.2026 16:30 2 articles · 7h ago

    Maintainer account ships malicious @dforge-core/dforge-mcp releases with GHAPPIER loader

    Exploitation Observed

    Someone used the maintainer account of @dforge-core/dforge-mcp for 105 minutes on September 9, changed the release workflow so pushes to the main branch triggered publication, and pushed malicious releases 0.2.20 and 0.2.21; 0.2.21 carried the GHAPPIER loader through GitHub Actions OIDC trusted publishing.

    Show sources
  2. 20.09.2026 16:30 1 articles · 1d ago

    CloudSEK traces GHAPPIER across 65 public repositories, 73 infected files and 22 accounts

    Campaign Scope Update

    CloudSEK said it could not establish how the maintainer account was accessed, suspected a developer machine infected by a malicious extension or package, traced GHAPPIER across at least 65 public repositories, 73 infected files and 22 accounts, and found no evidence of a successful compromise of any organization.

    Show sources