GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign
2026-09-20 • Cloud SEK •
https://www.cloudsek.com/blog/ghappier-malware-loader-npm-supply-chain-attack
Attachments
source_4015.pdf (2 MB)
CloudSEK linked the GHAPPIER loader operation to the DPRK-associated PolinRider campaign after finding a byte-identical loader beside a payload that used PolinRider's published Ethereum dead-drop wallet. The operator compromised developer credentials, modified at least 65 repositories, and briefly published a malicious `@dforge-core/dforge-mcp` 0.2.21 release through a legitimate GitHub Actions trusted-publishing workflow. Its four-stage chain delivered a self-deleting JavaScript remote shell with a hard-coded socket C2, while the related NullReceiver payload decoded rotating C2 addresses from Ethereum recipient fields. CloudSEK established the technical campaign links but inherited, rather than independently confirmed, the North Korean attribution.