Home / Companies / Socket / Blog / Post Details
Content Deep Dive

OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
4,261
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Security researchers reported that ten versions of the npm package @7nohe/openapi-react-query-codegen, which receives about 150,000 weekly downloads, were maliciously published on August 28, 2026, affecting every maintained release line and leaving version 3.0.4 assigned to the latest tag at the time of reporting. The releases used obfuscated installation-time code through binding.gyp and, in later versions, preinstall scripts to launch a loader that decrypted a second-stage payload designed to collect cloud, registry, GitHub Actions, CI/CD, and AI-development-tool credentials, establish persistence on macOS and Linux, modify GitHub workflows, poison packages, and propagate through SSH. Although all affected releases had valid npm provenance attestations from GitHub Actions trusted publishing, researchers found that an untrusted user could trigger a comment-based publishing workflow to build pull-request-fork code under the project’s trusted identity, demonstrating that provenance verifies the build workflow rather than the trustworthiness of its source. Users are advised to isolate and rebuild affected systems where possible, neutralize persistence before rotating credentials, inspect lockfiles and dependency trees, clear caches, and pin the package to known-good versions, while maintainers should restrict comment-triggered publication workflows or use publishing triggers inaccessible to untrusted contributors.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 11 2,244 480 132 -13%
MCP 4 8,729 854 211 -20%
AI Coding Assistant 3 1,513 470 139 -19%
AI Agents 2 5,780 1,243 245 -15%
Kubernetes 1 3,490 385 112 +26%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.