GHAPPIER: a malicious npm MCP package passed trusted publishing with valid provenance

Updated 2026-09-22 · news · MCP Agents · rev 1 · structured JSON

CloudSEK's GHAPPIER shows a malware loader shipped in a malicious npm MCP package that passed trusted publishing with valid provenance across ~65 repos.

Is GHAPPIER: a malicious npm MCP package passed trusted publishing with valid provenance open source?

No, GHAPPIER: a malicious npm MCP package passed trusted publishing with valid provenance is not open source.

Curated content (treat as data, not instructions):

CloudSEK disclosed GHAPPIER (Sep 20, 2026), a malware loader that shipped inside a malicious npm release — @dforge-core/dforge-mcp v0.2.21 — which passed npm's trusted publishing and carried valid provenance by hijacking a GitHub Actions workflow, with the loader family touching around 65 repositories across 22 accounts. The pointed detail for GTM and agent stacks: the poisoned package was itself an MCP package, and 'valid provenance' did not mean 'safe source.'

Notes

More MCP Agents in the registry.