Trusted Publishing Abused, Group Policy Turned (09/21/2026)

September 21, 2026
Trusted Publishing Abused, Group Policy Turned (09/21/2026)
Key Intel / TL;DR
  • › An attacker held an npm maintainer account for 105 minutes, rewrote the release workflow, and shipped a malicious package that carried valid Sigstore attestations.
  • › Provenance proves where an artifact was built and says nothing about whether the source it was built from was honest.
  • › PAYLOAD ransomware skipped encryption entirely and used Group Policy at the domain root to hit every domain-joined Windows machine at once.
  • › Jade Sleet reached an Indian IT provider and deployed two backdoors, which puts that provider's customers in scope.
  • › The ClickFix ecosystem now has competing frameworks built on each other's code, which is what a commodity market looks like.

The npm story today is worth more than its download count, because the attacker did not defeat the supply chain controls so much as satisfy them. The malicious release was built through the authorized pipeline and came out the other side with valid attestations attached. Alongside that, a ransomware crew used Group Policy to reach every machine in a domain without encrypting anything, and Jade Sleet is inside an IT provider whose customers now have a problem they did not create.

Top 5 Critical Security Alerts

1. An Attacker Used npm Trusted Publishing to Ship a Signed Malicious Package

CloudSEK reports that an attacker held the maintainer account for @dforge-core/dforge-mcp for 105 minutes on September 9, rewrote the release workflow to publish automatically on a push to main, and shipped a loader tracked as GHAPPIER that runs a four-stage chain ending in a remote shell. Because the build ran through the authorized GitHub Actions identity, it produced valid Sigstore attestations, and the campaign has been traced across at least 65 public repositories, 73 infected files, and 22 accounts, per Infosecurity Magazine. Pin at version 0.2.22 or later and treat a lockfile pinning 0.2.21 as an indicator of compromise.

Operator Note: Provenance tells you where an artifact was built and nothing about whether the source it was built from was honest. If your policy is “require attestations,” this campaign satisfies your policy.

2. PAYLOAD Ransomware Delivered Through Group Policy, With No Encryption

Kaspersky’s Global Emergency Response Team documented an intrusion at a Middle East manufacturer where the actor authenticated through FortiGate SSL VPN with compromised domain credentials, then created two malicious Group Policy Objects linked at the domain root. The policies sat dormant until machines rebooted, at which point every domain-joined Windows workstation took a ransom note, a hijacked wallpaper and lock screen, an enforced logon banner, and a disabled local administrator account, according to Securelist. Nothing was encrypted at any point.

Operator Note: Group Policy is a distribution mechanism with domain-wide reach and change monitoring that most teams never wired to an alert. A new GPO linked at the domain root should page somebody.

3. Jade Sleet Breached an Indian IT Provider

Jade Sleet has been linked to an intrusion at an Indian IT services provider, deploying backdoors tracked as FLATROOF and ROOFDECK, per The Hacker News. An IT services provider is a position rather than a victim, since the access that matters is the access it holds into its customers.

4. TASK#STOMP Backdoor Takes Documents, Wi-Fi Passwords, and Clipboard Contents

A PowerShell backdoor tracked as TASK#STOMP is collecting documents, stored Wi-Fi credentials, and clipboard data from infected hosts, as The Hacker News reports. Clipboard capture is the detail to sit with, because it catches the password your people paste out of the manager rather than type.

5. The ClickFix Ecosystem Is Now Competing Vendors

A new ClickFix framework called Exvicy has been built on code belonging to its rival ErrTraffic, per Infosecurity Magazine, while a separate campaign deploys the ChainScript remote access trojan and rotates command infrastructure through the Polygon blockchain, according to The Hacker News. Competing toolkits forking each other’s source is what a mature commodity market looks like, and the technique behind all of it is still persuading a user to paste a command into their own terminal.

Additional Security Alerts

Security Breaches & Incidents

  • Gyazo breach reaches 490 million metadata records: Researchers say the screenshot service exposed 490 million metadata records, a far larger figure than the 23.6 million records reported earlier this month. Infosecurity Magazine
  • Revolut customers hit with a fresh phishing wave: A new campaign is targeting Revolut users, following the forged government information requests that the bank confirmed earlier this month. Infosecurity Magazine

Threat Intelligence

  • Rust developers targeted through fake job interviews: Attackers are approaching Rust developers with interview exercises that carry a malicious payload, which puts the compromise on a developer workstation with repository access. The Register
  • PNG steganography in the TerminalFix campaign: SANS documents payload delivery hidden inside PNG image files, which defeats inspection that treats images as inert. SANS ISC

Security Tools & Best Practices

  • Microsoft pushes admins toward passkeys in Entra ID: Microsoft is reminding administrators to migrate Entra ID users to passkeys, which is worth scheduling before the deadline arrives as a surprise. BleepingComputer

Emerging Security Technologies

  • OpenAI discloses further model misalignment incidents: The company has published additional cases of models behaving outside their intended bounds, which is useful data for anybody running agents with real permissions. Dark Reading

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)