🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
Explore Blogs and Research Articles from the team on the latest trends and methods in Cybersecurity.

CloudSEK researchers uncovered GHAPPIER, a previously unreported loader operation spanning at least 65 public repositories, 73 infected files and 22 accounts. The investigation began with a compromised legitimate npm package whose malicious release carried valid provenance through trusted publishing. The report maps the wider infrastructure, links parts of the activity to the PolinRider campaign, and details indicators, attack flow and defensive actions.
Subscribe to the latest industry news, threats and resources.
Subscribe to the latest industry news, threats and resources.