


Perceptive Security
SOC/SIEM Consultancy

Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Published:
28 augustus 2026 om 22:49:35
Alert date:
29 augustus 2026 om 00:01:24
Source:
socket.dev
Supply Chain & Dependencies, Ransomware & Malware
On August 28, 2026, ten malicious versions of the npm package @7nohe/openapi-react-query-codegen were published in two waves as part of the Mini Shai-Hulud supply chain attack. A threat actor abused a comment-triggered GitHub Actions publishing workflow, allowing any GitHub account to publish fork code under the repository's trusted OIDC identity by simply commenting 'npm publish' on a pull request. All ten malicious versions carry valid npm provenance attestations, meaning npm audit signatures will not flag them. The malicious releases execute a bundled obfuscated JavaScript loader (3FWCvzduYZg.js) at install time, which decrypts an AES-128-GCM payload, writes it to a temp file, executes it, and deletes it. The latest tag still resolves to the malicious version 3.0.4 at time of writing. Users are advised to pin to known-good versions (0.5.3, 1.6.2, 2.2.0, or 3.0.2), clear caches, and treat any machine that installed an affected version as compromised. The threat actor's GitHub account (p00paboot) staged the malicious code via a fork of the repository.
Technical details
Mitigation steps:
Affected products:
@7nohe/openapi-react-query-codegen
Related links:
https://socket.dev/blog/openapi-react-query-codegen-npm-compromise?utm_medium=feed
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/0.0.0-365d4eb738d3146583431948d3ba6e27a32556be
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/0.5.4
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/0.5.5
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/1.6.3
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/1.6.4
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/2.2.1
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/2.2.2
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/3.0.3
https://socket.dev/npm/package/@7nohe/openapi-react-query-codegen/overview/3.0.4
https://cdn.sanity.io/images/cgdhsj6q/production/f89515c4cf115765f856576d91f3c9981759176d-1342x815.png?w=1600&q=95&fit=max&auto=format
https://raw.githubusercontent.com/oven-sh/bun/refs/heads/main/src/runtime/cli/install.sh
https://github.com/p00paboot
https://github.com/p00paboot/openapi-react-query-codegen
Related CVE's:
Related threat actors:
IOC's:
github.com/p00paboot, github.com/p00paboot/openapi-react-query-codegen, 365d4eb738d3146583431948d3ba6e27a32556be, d3246926b20a8d021ed7de0ac8e9eee1dda986088f84ba18f31cb2042a121f5d, 59370c67b54a0ccaedd265e2356f04540b2fba1e1845300ef6de4d5437d99380, b49afb7dba64cd99b357ce7c652c823a3707f28e130bd5c6645851a7adc030d6, 3FWCvzduYZg.js, binding.gyp, is_it_this_simple.js, @7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be, @7nohe/openapi-react-query-codegen@0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab, @7nohe/openapi-react-query-codegen@0.5.4, @7nohe/openapi-react-query-codegen@0.5.5, @7nohe/openapi-react-query-codegen@1.6.3, @7nohe/openapi-react-query-codegen@1.6.4, @7nohe/openapi-react-query-codegen@2.2.1, @7nohe/openapi-react-query-codegen@2.2.2, @7nohe/openapi-react-query-codegen@3.0.3, @7nohe/openapi-react-query-codegen@3.0.4
This article was created with the assistance of AI technology by Perceptive.
