GHAPPIER loader in @dforge-core/dforge-mcp malicious npm release
Malware Activity
Summary
Hide ▲
Show ▼
A malicious npm release of @dforge-core/dforge-mcp shipped the GHAPPIER loader with valid provenance, affecting 65 public repositories, 73 infected files, and 22 accounts. The release used GitHub Actions and OIDC trusted publishing, allowing the package to pass provenance checks while still carrying malicious code. The loader activated when the MCP server launched and opened a staged chain that ended in a self-deleting remote shell.
Related Happenings
ViteVenom malicious npm packages delivering blockchain-backed RAT
Malware Activity
H score3
First: 17.07.2026 21:54
Last: 17.07.2026 21:54
Sources 1
About this happening:
A cluster of seven malicious npm packages has targeted the Vite frontend ecosystem, delivering a blockchain-backed RAT loader that can harvest credentials and exfiltra...
ViteVenom malicious npm packages delivering blockchain-backed RAT
Malware ActivityAbout this happening: A cluster of seven malicious npm packages has targeted the Vite frontend ecosystem, delivering a blockchain-backed RAT loader that can harvest credentials and exfiltra...
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
@Injectivelabs/[email protected] wallet-stealing package
Malware Activity
H score30
First: 10.07.2026 20:29
Last: 10.07.2026 20:29
Sources 1
About this happening:
The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
@Injectivelabs/[email protected] wallet-stealing package
Malware ActivityAbout this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
Timeline
-
21.09.2026 16:30 2 articles · 7h ago
Maintainer account ships malicious @dforge-core/dforge-mcp releases with GHAPPIER loader
Exploitation ObservedSomeone used the maintainer account of @dforge-core/dforge-mcp for 105 minutes on September 9, changed the release workflow so pushes to the main branch triggered publication, and pushed malicious releases 0.2.20 and 0.2.21; 0.2.21 carried the GHAPPIER loader through GitHub Actions OIDC trusted publishing.
Show sources
- Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign — www.infosecurity-magazine.com — 21.09.2026 16:30
- Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign — www.infosecurity-magazine.com — 21.09.2026 16:30
-
20.09.2026 16:30 1 articles · 1d ago
CloudSEK traces GHAPPIER across 65 public repositories, 73 infected files and 22 accounts
Campaign Scope UpdateCloudSEK said it could not establish how the maintainer account was accessed, suspected a developer machine infected by a malicious extension or package, traced GHAPPIER across at least 65 public repositories, 73 infected files and 22 accounts, and found no evidence of a successful compromise of any organization.
Show sources
- Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign — www.infosecurity-magazine.com — 21.09.2026 16:30