A supply-chain attack involving the GHAPPIER malware campaign compromised the legitimate npm package @dforge-core/dforge-mcp, briefly distributing a self-deleting backdoor. The incident began on September 9, 2026, when an attacker exploited the maintainer's account for about 105 minutes. Malware compromised cached Git credentials, enabling attackers to impersonate the maintainer across different GitHub repositories.

They also altered three lines of code, causing every push to the main branch to trigger the release workflow. However, researchers warned that simply withdrawing the malicious release may not fully protect users who installed version 0.2.21. It was built through GitHub Actions using OpenID Connect trusted publishing, and its build attestation remains recorded in Sigstore’s append-only transparency log.

A single line near the end of a 99KB file harbored malicious code, initiating a four-stage infection process. The final stage's implant deletes itself from disk immediately after execution, complicating traditional file-based investigations. Researchers discovered a second payload family in another victim repository, potentially linking the activity to the PolinRider campaign, which has been linked to DPRK-linked activity.

It embeds configuration data within the recipient address of an empty blockchain transaction, creating a resilient communication channel that is tough to disrupt. Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team.