top of page
perceptive_background_267k.jpg

Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Published:

28 augustus 2026 om 22:49:35

Alert date:

29 augustus 2026 om 00:01:24

Source:

socket.dev

Click to open the original link from this advisory

Supply Chain & Dependencies, Ransomware & Malware

On August 28, 2026, ten malicious versions of the npm package @7nohe/openapi-react-query-codegen were published in two waves as part of the Mini Shai-Hulud supply chain attack. A threat actor abused a comment-triggered GitHub Actions publishing workflow, allowing any GitHub account to publish fork code under the repository's trusted OIDC identity by simply commenting 'npm publish' on a pull request. All ten malicious versions carry valid npm provenance attestations, meaning npm audit signatures will not flag them. The malicious releases execute a bundled obfuscated JavaScript loader (3FWCvzduYZg.js) at install time, which decrypts an AES-128-GCM payload, writes it to a temp file, executes it, and deletes it. The latest tag still resolves to the malicious version 3.0.4 at time of writing. Users are advised to pin to known-good versions (0.5.3, 1.6.2, 2.2.0, or 3.0.2), clear caches, and treat any machine that installed an affected version as compromised. The threat actor's GitHub account (p00paboot) staged the malicious code via a fork of the repository.

Technical details

Mitigation steps:

Affected products:

@7nohe/openapi-react-query-codegen

Related links:

Related CVE's:

Related threat actors:

IOC's:

github.com/p00paboot, github.com/p00paboot/openapi-react-query-codegen, 365d4eb738d3146583431948d3ba6e27a32556be, d3246926b20a8d021ed7de0ac8e9eee1dda986088f84ba18f31cb2042a121f5d, 59370c67b54a0ccaedd265e2356f04540b2fba1e1845300ef6de4d5437d99380, b49afb7dba64cd99b357ce7c652c823a3707f28e130bd5c6645851a7adc030d6, 3FWCvzduYZg.js, binding.gyp, is_it_this_simple.js, @7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be, @7nohe/openapi-react-query-codegen@0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab, @7nohe/openapi-react-query-codegen@0.5.4, @7nohe/openapi-react-query-codegen@0.5.5, @7nohe/openapi-react-query-codegen@1.6.3, @7nohe/openapi-react-query-codegen@1.6.4, @7nohe/openapi-react-query-codegen@2.2.1, @7nohe/openapi-react-query-codegen@2.2.2, @7nohe/openapi-react-query-codegen@3.0.3, @7nohe/openapi-react-query-codegen@3.0.4

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page