socket-dev · Crawled Sep 2, 2026

OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

21 IoCs
Read original article ↗

AI Summary

The npm package @7nohe/openapi-react-query-codegen was compromised in a supply chain attack dubbed 'Mini Shai-Hulud', where ten malicious versions were published using a comment-triggered GitHub Actions workflow vulnerability. The malicious code executes during installation via an obfuscated JavaScript loader (3FWCvzduYZg.js), which decrypts and runs a second-stage payload designed to steal cloud credentials, package registry tokens, GitHub Actions secrets, and AI agent configurations. The payload includes self-propagation capabilities, including SSH-based lateral movement, GitHub Actions workflow tampering, and package poisoning across npm, JFrog, RubyGems, and PyPI. All malicious versions carry valid npm provenance attestations, making them appear legitimate despite containing attacker-controlled code.

AI-extracted · verify before operational use

Indicators of Compromise 21 extracted

Type Value Detail
Package @7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be Details →
Package @7nohe/openapi-react-query-codegen@0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab Details →
Package @7nohe/[email protected] Details →
Package @7nohe/[email protected] Details →
Package @7nohe/[email protected] Details →
Package @7nohe/[email protected] Details →
Package @7nohe/[email protected] Details →
Package @7nohe/[email protected] Details →
Package @7nohe/[email protected] Details →
Package @7nohe/[email protected] Details →
Filename 3FWCvzduYZg.js Details →
Filename binding.gyp Details →
Filename ai_init.js Details →
Filename ai_setup.sh Details →
Filename is_it_this_simple.js Details →
Filename nu.js Details →
GitHub Repo p00paboot/openapi-react-query-codegen Details →
GitHub User p00paboot Details →
SHA-256 b49afb7dba04cd99b357ce7c652c823a3707f28e130bd5c6645851a7adc030d659370c67b54a0ccaedd265e2356f04540b2fba1e1845300ef6de4d5437d99380 Details →
SHA-256 d3246926b20a8d021ed7de0ac8e9eee1dda986088f84ba18f31cb2042a121f5d Details →
Domain metadata[.]google[.]internal Details →