GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign
CloudSEK researchers uncovered GHAPPIER, a previously unreported loader operation spanning at least 65 public repositories, 73 infected files and 22 accounts. The investigation began with a compromised legitimate npm package whose malicious release carried valid provenance through trusted publishing. The report maps the wider infrastructure, links parts of the activity to the PolinRider campaign, and details indicators, attack flow and defensive actions.