OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
AI Summary
The npm package @7nohe/openapi-react-query-codegen was compromised in a supply chain attack dubbed 'Mini Shai-Hulud', where ten malicious versions were published using a comment-triggered GitHub Actions workflow vulnerability. The malicious code executes during installation via an obfuscated JavaScript loader (3FWCvzduYZg.js), which decrypts and runs a second-stage payload designed to steal cloud credentials, package registry tokens, GitHub Actions secrets, and AI agent configurations. The payload includes self-propagation capabilities, including SSH-based lateral movement, GitHub Actions workflow tampering, and package poisoning across npm, JFrog, RubyGems, and PyPI. All malicious versions carry valid npm provenance attestations, making them appear legitimate despite containing attacker-controlled code.
AI-extracted · verify before operational use
Indicators of Compromise 21 extracted
| Type | Value | Detail |
|---|---|---|
| Package | @7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be | Details → |
| Package | @7nohe/openapi-react-query-codegen@0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab | Details → |
| Package | @7nohe/[email protected] | Details → |
| Package | @7nohe/[email protected] | Details → |
| Package | @7nohe/[email protected] | Details → |
| Package | @7nohe/[email protected] | Details → |
| Package | @7nohe/[email protected] | Details → |
| Package | @7nohe/[email protected] | Details → |
| Package | @7nohe/[email protected] | Details → |
| Package | @7nohe/[email protected] | Details → |
| Filename | 3FWCvzduYZg.js | Details → |
| Filename | binding.gyp | Details → |
| Filename | ai_init.js | Details → |
| Filename | ai_setup.sh | Details → |
| Filename | is_it_this_simple.js | Details → |
| Filename | nu.js | Details → |
| GitHub Repo | p00paboot/openapi-react-query-codegen | Details → |
| GitHub User | p00paboot | Details → |
| SHA-256 | b49afb7dba04cd99b357ce7c652c823a3707f28e130bd5c6645851a7adc030d659370c67b54a0ccaedd265e2356f04540b2fba1e1845300ef6de4d5437d99380 | Details → |
| SHA-256 | d3246926b20a8d021ed7de0ac8e9eee1dda986088f84ba18f31cb2042a121f5d | Details → |
| Domain | metadata[.]google[.]internal | Details → |