Attackers compromised a maintainer account for the legitimate @dforge-core/dforge-mcp npm package, altered its release workflow, and published the previously unreported GHAPPIER loader in version 0.2.21. The release carried valid GitHub Actions OIDC provenance because the adversary had repository push access and used the trusted CI identity, rather than exploiting GitHub, npm, or the package’s trusted-publishing mechanism. GHAPPIER activates when the MCP server starts and executes a four-stage chain culminating in a self-deleting, general-purpose remote shell.
CloudSEK reported that the activity involved 65 repositories and 22 accounts across GitHub and npm, and assessed related payloads as operating alongside the DPRK-linked PolinRider campaign; independent confirmation of North Korean attribution and successful victim compromises was not available. Organizations should pin @dforge-core/dforge-mcp to version 0.2.22, treat lockfiles referencing 0.2.21 as a potential exposure indicator, investigate residual payload-chain artifacts, and monitor package release workflows for unauthorized trigger or publishing changes.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
CloudSEK reported the previously unreported GHAPPIER loader campaign, identifying at least 65 public repositories, 73 infected files, and 22 accounts. It linked related payloads to PolinRider but could not independently confirm reported North Korean attribution, and found no evidence of a successful organizational compromise.
Fourteen minutes after modifying workflow triggers so every push to main invoked the release workflow, the attacker rewrote the workflow to enable unattended publishing. The resulting valid provenance attestation reflected the CI build environment, not whether the committed code was benign.
Attackers distributed the GHAPPIER loader through version 0.2.21 of the legitimate @dforge-core/dforge-mcp package using GitHub Actions OIDC trusted publishing. The release was the latest version for 35 minutes and 38 seconds; GHAPPIER executed only when the MCP server launched and ultimately deployed a self-deleting remote shell.
The attacker issued an initial malicious release of @dforge-core/dforge-mcp version 0.2.20, but the release failed and broke package installation.
An attacker used the @dforge-core/dforge-mcp maintainer account for 105 minutes and already had permission to push to the repository's main branch. CloudSEK could not determine how access was obtained.
OpenSourceMalware had tracked the PolinRider payload campaign since March 2026. A payload found in a separate victim repository later exactly matched this campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.