CloudSEK researchers uncovered GHAPPIER, a previously unreported loader operation spanning at least 65 public repositories, 73 infected files and 22 accounts. The investigation began with a compromised legitimate npm package whose malicious release carried valid provenance through trusted...
www.cloudsek.com
The investigation began with a compromised legitimate npm package whose malicious release carried valid provenance through trusted publishing. The report maps the wider infrastructure, links parts of the activity to the PolinRider campaign, and details indicators, attack flow and defensive actions.