A malicious npm package was published with **completely valid provenance**.
Wait... WHAT?! 😬
That's what happened in the GHAPPIER software supply chain attack.
And here's the fascinating part:
**The provenance wasn't fake.**
The security control WORKED.
The attackers had gained legitimate access to the source repository and changed the code and publishing workflow.
So the totally legitimate CI/CD system built the malicious code.
The 100% legitimate publishing process published it.
And the provenance very legitimately told us when, where and how that artifact was built.
Because provenance does NOT mean:
"This code is safe."
I made a very short video explaining what happened AND, of course, what developers can do to protect themselves:
🎥
twp.ai/E5FfB0