As cited
Copy frozen at (site build).
threat intel
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
On August 28, 2026, a threat actor published ten malicious versions of the npm package @7nohe/openapi-react-query-codegen by exploiting a comment-triggered GitHub Actions workflow that lacked proper authorization checks. The malicious releases carry valid npm provenance signatures and execute obfuscated code during installation that harvests credentials, modifies other packages, and establishes persistence on developer machines and continuous integration runners. The attacker abused a publishing workflow that allowed any GitHub account to trigger a package release from a fork's code by commenting on a pull request.
Why it matters: Developers using any of the ten affected versions face immediate host compromise and credential exposure across GitHub, npm, PyPI, RubyGems, JFrog, cloud providers, and artificial intelligence (AI) agent configurations; organizations must isolate affected machines, treat them as compromised, revoke all credentials accessible from those environments, and audit GitHub and package-registry logs for signs of lateral movement and package poisoning.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
On August 28, 2026, a threat actor published ten malicious versions of the npm package @7nohe/openapi-react-query-codegen by exploiting a comment-triggered GitHub Actions workflow that lacked proper authorization checks. The malicious releases carry valid npm provenance signatures and execute obfuscated code during installation that harvests credentials, modifies other packages, and establishes persistence on developer machines and continuous integration runners. The attacker abused a publishing workflow that allowed any GitHub account to trigger a package release from a fork's code by commenting on a pull request.
Why it matters: Developers using any of the ten affected versions face immediate host compromise and credential exposure across GitHub, npm, PyPI, RubyGems, JFrog, cloud providers, and artificial intelligence (AI) agent configurations; organizations must isolate affected machines, treat them as compromised, revoke all credentials accessible from those environments, and audit GitHub and package-registry logs for signs of lateral movement and package poisoning.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
On August 28, 2026, a threat actor published ten malicious versions of the npm package @7nohe/openapi-react-query-codegen by exploiting a comment-triggered GitHub Actions workflow that lacked proper authorization checks. The malicious releases carry valid npm provenance signatures and execute obfuscated code during installation that harvests credentials, modifies other packages, and establishes persistence on developer machines and continuous integration runners. The attacker abused a publishing workflow that allowed any GitHub account to trigger a package release from a fork's code by commenting on a pull request.
Why it matters: Developers using any of the ten affected versions face immediate host compromise and credential exposure across GitHub, npm, PyPI, RubyGems, JFrog, cloud providers, and artificial intelligence (AI) agent configurations; organizations must isolate affected machines, treat them as compromised, revoke all credentials accessible from those environments, and audit GitHub and package-registry logs for signs of lateral movement and package poisoning.
- Source published
- First seen by Cybersecurity Tracker