{
  "$schema_doc": "https://gtmstacker.com/registry/schema/entry.schema.json",
  "stability": "emerging",
  "generator": "agentic-media-registry",
  "generated_at": "2026-09-22T00:00:00Z",
  "id": "com.gtmstacker.registry/news/ghappier-npm-attack",
  "type": "news",
  "slug": "ghappier-npm-attack",
  "canonical_url": "https://gtmstacker.com/registry/news/ghappier-npm-attack/",
  "title": "GHAPPIER: a malicious npm MCP package passed trusted publishing with valid provenance",
  "description": "CloudSEK disclosed GHAPPIER (Sep 20, 2026), a malware loader that shipped inside a malicious npm release — @dforge-core/dforge-mcp v0.2.21 — which passed npm's trusted publishing and carried valid provenance by hijacking a GitHub Actions workflow, with the loader family touching around 65 repositories across 22 accounts. The pointed detail for GTM and agent stacks: the poisoned package was itself an MCP package, and 'valid provenance' did not mean 'safe source.'",
  "category": "mcp-agents",
  "tags": [
    "mcp-agents",
    "news",
    "supply-chain",
    "agent-security",
    "governance"
  ],
  "status": "active",
  "revision": 1,
  "content_hash": "18ff189670a3339f3360706fbd891204005d35ccaadb505ccb6356667f84325f",
  "date_published": "2026-09-22T00:00:00Z",
  "date_modified": "2026-09-22T00:00:00Z",
  "source": {
    "name": "CloudSEK",
    "url": "https://www.cloudsek.com/blog/ghappier-malware-loader-npm-supply-chain-attack"
  },
  "one_liner": "CloudSEK's GHAPPIER shows a malware loader shipped in a malicious npm MCP package that passed trusted publishing with valid provenance across ~65 repos.",
  "open_source": "no",
  "self_hostable": "unknown",
  "pricing_model": "unknown",
  "aliases": [],
  "alternatives": [],
  "secondary_categories": [],
  "last_verified": "2026-09-22",
  "evidence": {
    "claim_type": "mixed",
    "source_id": "https://www.cloudsek.com/blog/ghappier-malware-loader-npm-supply-chain-attack",
    "note": "CloudSEK first-party research + security-press coverage (Infosecurity Magazine), WebFetch-read 2026-09-22. Attack ~Sep 9; disclosed Sep 20. Malicious @dforge-core/dforge-mcp v0.2.21 passed npm trusted publishing with valid provenance via a hijacked GitHub Actions workflow; loader family spans ~65 repos / 22 accounts. '65 repos' = repos the loader family touched, not 65 compromised orgs; no confirmed org compromise. Fix: pin v0.2.22, treat v0.2.21 lockfiles as suspect."
  },
  "lead": "CloudSEK disclosed GHAPPIER (Sep 20, 2026), a malware loader that shipped inside a malicious npm release — @dforge-core/dforge-mcp v0.2.21 — which passed npm's trusted publishing and carried valid provenance by hijacking a GitHub Actions workflow, with the loader family touching around 65 repositories across 22 accounts. The pointed detail for…",
  "chunks": [
    {
      "index": 0,
      "heading_path": [],
      "est_tokens": 117,
      "text": "CloudSEK disclosed GHAPPIER (Sep 20, 2026), a malware loader that shipped inside a malicious npm release — @dforge-core/dforge-mcp v0.2.21 — which passed npm's trusted publishing and carried valid provenance by hijacking a GitHub Actions workflow, with the loader family touching around 65 repositories across 22 accounts. The pointed detail for GTM and agent stacks: the poisoned package was itself an MCP package, and 'valid provenance' did not mean 'safe source.'"
    },
    {
      "index": 1,
      "heading_path": [
        null,
        "Notes"
      ],
      "est_tokens": 407,
      "text": "which passed npm's trusted publishing and carried valid provenance by hijacking a GitHub Actions workflow, with the loader family touching around 65 repositories across 22 accounts. The pointed detail for GTM and agent stacks: the poisoned package was itself an MCP package, and 'valid provenance' did not mean 'safe source.'\n\n- What is confirmed: CloudSEK's first-party disclosure (WebFetch 2026-09-22, corroborated by Infosecurity Magazine). The malicious @dforge-core/dforge-mcp v0.2.21 passed npm trusted publishing with valid provenance by hijacking a GitHub Actions workflow; the loader family touched ~65 repos across 22 accounts. Attack ~Sep 9, disclosed Sep 20.\n- What to read carefully: \"~65 repositories\" means repos the loader family touched, not 65 independently compromised organizations, and no successful org compromise is confirmed. The remediation is concrete: pin v0.2.22 and treat any v0.2.21 lockfile as suspect.\n- The GTM-stack read: this is the direct sequel to the RubyGems agent-attack report already in this registry — same theme, new registry, sharper twist. Provenance and \"trusted publishing\" are supposed to be the answer to supply-chain doubt, and here they were satisfied while malware shipped, in an MCP package no less. If your stack installs MCP servers or agent packages from public registries, provenance is necessary but not sufficient: pin versions, scan post-install behavior, and scope what freshly installed agent packages can reach.\n- Curated from the GTM Stacker signal registry (2026-09-22 pass: viral-posts brief, cross-corroborated by the studio news lane's supply-chain items)."
    }
  ],
  "alternates": {
    "markdown": "https://gtmstacker.com/registry/news/ghappier-npm-attack/index.md",
    "html": "https://gtmstacker.com/registry/news/ghappier-npm-attack/",
    "json": "https://gtmstacker.com/registry/news/ghappier-npm-attack/index.json"
  },
  "jsonld": {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "WebSite",
        "@id": "https://gtmstacker.com/#website",
        "url": "https://gtmstacker.com/",
        "name": "GTM Stacker Agent Registry",
        "description": "A daily-updated, agent-native registry of open-source tool discoveries, tool updates, and curated news for the go-to-market / RevOps engineering niche. Machine-readable first: agents can discover, parse, page, and delta-sync it without scraping HTML.",
        "inLanguage": "en",
        "publisher": {
          "@id": "https://gtmstacker.com/#organization"
        }
      },
      {
        "@type": "Organization",
        "@id": "https://gtmstacker.com/#organization",
        "name": "GTM Stacker",
        "url": "https://gtmstacker.com",
        "description": "The growth-systems practice of Theo Popov: AI-native enrichment, outbound, content engines and internal tooling for startups and venture programs. Its agent-native media property, the GTM Stacker Agent Registry, maintains a daily-updated catalog of open-source go-to-market and RevOps tools that both people and AI engines can discover, compare, and cite.",
        "foundingDate": "2024-08",
        "knowsAbout": [
          "go-to-market engineering",
          "RevOps",
          "sales automation",
          "marketing operations",
          "open-source software",
          "AI agents"
        ],
        "founder": {
          "@type": "Person",
          "@id": "https://gtmstacker.com/#founder",
          "name": "Theo Popov",
          "jobTitle": "Growth Operations & GTM Systems",
          "url": "https://gtmstacker.com/about/",
          "sameAs": [
            "https://www.linkedin.com/in/theo-popov",
            "https://x.com/Theo_Popov",
            "https://github.com/theopopov"
          ],
          "worksFor": {
            "@id": "https://gtmstacker.com/#organization"
          }
        },
        "sameAs": [
          "https://www.linkedin.com/company/gtmstacker",
          "https://www.youtube.com/@gtmstacker",
          "https://www.instagram.com/gtmstacker/",
          "https://www.tiktok.com/@gtmstacker"
        ],
        "mainEntityOfPage": "https://gtmstacker.com/registry/about/"
      },
      {
        "@type": "NewsArticle",
        "@id": "https://gtmstacker.com/registry/news/ghappier-npm-attack/#article",
        "headline": "Provenance is not trust: a signed, 'trusted-published' npm MCP package still carried a malware loader — the agent supply chain's next soft spot",
        "description": "CloudSEK disclosed GHAPPIER (Sep 20, 2026), a malware loader that shipped inside a malicious npm release — @dforge-core/dforge-mcp v0.2.21 — which passed npm's trusted publishing and carried valid provenance by hijacking a GitHub Actions workflow, with the loader family touching around 65 repositories across 22 accounts. The pointed detail for GTM and agent stacks: the poisoned package was itself an MCP package, and 'valid provenance' did not mean 'safe source.'",
        "url": "https://gtmstacker.com/registry/news/ghappier-npm-attack/",
        "isPartOf": {
          "@id": "https://gtmstacker.com/#website"
        },
        "datePublished": "2026-09-22T00:00:00Z",
        "dateModified": "2026-09-22T00:00:00Z",
        "author": {
          "@id": "https://gtmstacker.com/#organization"
        },
        "publisher": {
          "@id": "https://gtmstacker.com/#organization"
        }
      },
      {
        "@type": "BreadcrumbList",
        "@id": "https://gtmstacker.com/registry/news/ghappier-npm-attack/#breadcrumb",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "GTM Stacker Registry",
            "item": "https://gtmstacker.com/registry/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "MCP Agents",
            "item": "https://gtmstacker.com/registry/category/mcp-agents/"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "GHAPPIER: a malicious npm MCP package passed trusted publishing with valid provenance",
            "item": "https://gtmstacker.com/registry/news/ghappier-npm-attack/"
          }
        ]
      }
    ]
  },
  "news": {
    "headline": "Provenance is not trust: a signed, 'trusted-published' npm MCP package still carried a malware loader — the agent supply chain's next soft spot",
    "mentions": []
  }
}
