Attackers used the maintainer account of the npm package @dforge-core/dforge-mcp for 105 minutes on 9 September to publish a previously unreported loader that CloudSEK tracks as GHAPPIER, and the release carried a genuine build attestation. Version 0.2.20 broke installation; 0.2.21 shipped the loader and held as the latest version for 35 minutes and 38 seconds. The attacker could already push to the main branch and changed three lines so that any push triggered the release workflow, then rewrote that workflow 14 minutes later so it could publish unattended. The build ran through GitHub Actions with OIDC trusted publishing, so the attestation sits in Sigstore's public log naming the attacker's own commit, and the release would pass npm audit signatures. CloudSEK's framing is the one to keep: "provenance attests where an artefact was built, not whether its source was honest." The loader was a single line inside a 99 KB file, opening a four-stage chain that ended in a general-purpose remote shell which deleted itself as it ran; it fired when the MCP server was launched rather than on install, so systems that installed 0.2.21 without starting it did not execute it. The activity spans at least 65 public repositories, 73 infected files and 22 accounts, and a second payload in another victim's repository matched PolinRider, the campaign OpenSourceMalware has tracked since March 2026 and which other researchers attribute to North Korea; a configuration step reads from an empty Ethereum transaction costing about $0.20, leaving no domain to seize. CloudSEK advises pinning 0.2.22, treating a lockfile that pins 0.2.21 as an indicator in itself, and alerting on changes to a release workflow's trigger block. No OSV or GitHub advisory had appeared at the time of the report.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-22 |
| Source | Infosecurity Magazine |
| Reliability | Tier 2 |