step-security · Crawled Sep 1, 2026

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

18 IoCs
Read original article ↗

AI Summary

On August 28, 2026, the npm package @7nohe/openapi-react-query-codegen was compromised via an exposed GitHub Actions workflow that allowed unauthorized publishing. An external attacker exploited a permissive release workflow triggered by a comment from any pull request participant, leading to the publication of ten malicious versions. These versions included obfuscated payloads and malicious preinstall hooks that executed during installation, downloading and running the Bun executable, probing for GitHub credentials, and exfiltrating sensitive data. The attack leveraged npm Trusted Publishing with GitHub Actions OIDC, allowing code execution without needing the maintainer's npm token.

AI-extracted · verify before operational use

Indicators of Compromise 18 extracted

Type Value Detail
Package @7nohe/openapi-react-query-codegen@0.5.4 Details →
Package @7nohe/openapi-react-query-codegen@0.5.5 Details →
Package @7nohe/openapi-react-query-codegen@1.6.3 Details →
Package @7nohe/openapi-react-query-codegen@1.6.4 Details →
Package @7nohe/openapi-react-query-codegen@2.2.1 Details →
Package @7nohe/openapi-react-query-codegen@2.2.2 Details →
Package @7nohe/openapi-react-query-codegen@3.0.3 Details →
Package @7nohe/openapi-react-query-codegen@3.0.4 Details →
Package @7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be Details →
Package @7nohe/openapi-react-query-codegen@0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab Details →
Filename 3FWCvzduYZg.js Details →
Filename binding.gyp Details →
Filename is_it_this_simple.js Details →
Filename nu.js Details →
Filename /tmp/trinnyyyy-*/bun Details →
Filename /tmp/*.js Details →
Filename /tmp/*/updater.py Details →
SHA-256 b24d121667f21f492cb9db34fbfd515d5922a8dd30b9c45215c7220abbb10ca8 Details →