step-security · Crawled Sep 1, 2026
@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow
18 IoCs
Read original article ↗
AI Summary
On August 28, 2026, the npm package @7nohe/openapi-react-query-codegen was compromised via an exposed GitHub Actions workflow that allowed unauthorized publishing. An external attacker exploited a permissive release workflow triggered by a comment from any pull request participant, leading to the publication of ten malicious versions. These versions included obfuscated payloads and malicious preinstall hooks that executed during installation, downloading and running the Bun executable, probing for GitHub credentials, and exfiltrating sensitive data. The attack leveraged npm Trusted Publishing with GitHub Actions OIDC, allowing code execution without needing the maintainer's npm token.
AI-extracted · verify before operational use
Indicators of Compromise 18 extracted
| Type | Value | Detail |
|---|---|---|
| Package | @7nohe/openapi-react-query-codegen@0.5.4 | Details → |
| Package | @7nohe/openapi-react-query-codegen@0.5.5 | Details → |
| Package | @7nohe/openapi-react-query-codegen@1.6.3 | Details → |
| Package | @7nohe/openapi-react-query-codegen@1.6.4 | Details → |
| Package | @7nohe/openapi-react-query-codegen@2.2.1 | Details → |
| Package | @7nohe/openapi-react-query-codegen@2.2.2 | Details → |
| Package | @7nohe/openapi-react-query-codegen@3.0.3 | Details → |
| Package | @7nohe/openapi-react-query-codegen@3.0.4 | Details → |
| Package | @7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be | Details → |
| Package | @7nohe/openapi-react-query-codegen@0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab | Details → |
| Filename | 3FWCvzduYZg.js | Details → |
| Filename | binding.gyp | Details → |
| Filename | is_it_this_simple.js | Details → |
| Filename | nu.js | Details → |
| Filename | /tmp/trinnyyyy-*/bun | Details → |
| Filename | /tmp/*.js | Details → |
| Filename | /tmp/*/updater.py | Details → |
| SHA-256 | b24d121667f21f492cb9db34fbfd515d5922a8dd30b9c45215c7220abbb10ca8 | Details → |