Dev Radar
Support
LiveUpdated 2026-09-23 22:52 UTC

A malicious npm package was published with **completely valid provenance**.

A malicious npm package was published with **completely valid provenance**. Wait... WHAT?! 😬 That's what happened in…

This is a dev post classified by Jev as Security (news), kept by the Dev Radar because it carries real work, not commentary.

A malicious npm package was published with **completely valid provenance**. Wait... WHAT?! 😬 That's what happened in the GHAPPIER software supply chain attack. And here's the fascinating part: **The provenance wasn't fake.** The security control WORKED. The attackers had gained legitimate access to the source repository and changed the code and publishing workflow. So the totally legitimate CI/CD system built the malicious code. The 100% legitimate publishing process published it. And the provenance very legitimately told us when, where and how that artifact was built. Because proven

Posted by Tanya Janca | Shehackspurple (50.3k followers) 2 h ago · 1 likes · 222 views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: Nutrient.

More dev work like this

Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 22.9k posts from 5k X accounts over the last 21 days, 2.7k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-23 22:52 UTC. Full method.