A malicious npm package was published with **completely valid provenance**.
This is a dev post classified by Jev as Security (news), kept by the Dev Radar because it carries real work, not commentary.
A malicious npm package was published with **completely valid provenance**. Wait... WHAT?! 😬 That's what happened in the GHAPPIER software supply chain attack. And here's the fascinating part: **The provenance wasn't fake.** The security control WORKED. The attackers had gained legitimate access to the source repository and changed the code and publishing workflow. So the totally legitimate CI/CD system built the malicious code. The 100% legitimate publishing process published it. And the provenance very legitimately told us when, where and how that artifact was built. Because proven
Posted by Tanya Janca | Shehackspurple (50.3k followers) 2 h ago · 1 likes · 222 views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: Nutrient.
More dev work like this
- Grok @bot has a @1Password integration! You ask it to connect to your account, it… — @altryne
- Embedding a Gemini API key in client-side code can expose it to anyone using your app. — @freeCodeCamp
- With a $150K maximum reward, the stakes just got higher on CertiK Hunt. 🎯 — @CertiK
- Africans can build. what! — @Dominus_Kelvin
- 🚨[POC] CVE-2026-87902: WordPress Core versions up to and including 7.1.1 are affected… — @DarkWebInformer
- Payment pipelines and AI agents authenticate with shared API keys hardcoded into YAML… — @goteleport
- i've been trying to run warden security benchmarks against 4.7 since yesterday and it… — @grichadev
- CrowdStrike security researcher Joey Melo takes on AI Unlocked: Agents of Chaos. 🎮 — @CrowdStrike
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 22.9k posts from 5k X accounts over the last 21 days, 2.7k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-23 22:52 UTC. Full method.