Ten malicious versions of @7nohe/openapi-react-query-codegen, a TanStack Query code generator with more than 150,000 weekly downloads, were published after an external GitHub user exploited its release workflow. The workflow accepted an exact npm-publish comment from any pull-request participant, checked out untrusted pull-request code, and used the repository's GitHub Actions OIDC trusted-publishing identity to release it; consequently, the malicious packages carried valid npm provenance attestations. At the time of reporting, npm's latest tag reportedly referenced malicious version 3.0.4.
The releases execute code during installation through preinstall hooks, malicious binding.gyp logic evaluated by node-gyp, or both, then launch an obfuscated second-stage payload. The malware downloads and executes Bun, probes Google Cloud metadata services, harvests credentials from cloud, GitHub, package registries, containers, Kubernetes, Vault, cryptocurrency wallets, messaging, VPN, and AI-development tools, and can propagate through accessible development environments; stolen data is exfiltrated through GitHub repositories labeled “Trinitite: Sponsored by Preview 2 Effects.” Organizations that installed affected versions with lifecycle scripts enabled should isolate and rebuild impacted systems, remove persistence and cached artifacts, and rotate all potentially exposed credentials from a clean environment using reviewed lockfiles and known-good releases.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
A commit containing the “Trinitite: Sponsored by Preview 2 Effects” marker was identified in a GitHub repository used by the Shai-Hulud variant. Researchers identified nine public repositories containing stolen credentials and documented new exfiltration, execution, and obfuscation indicators for the variant.
Researchers identified the malicious @7nohe/openapi-react-query-codegen releases, including versions 0.5.4 through 3.0.4 and two prereleases. Analysis found an obfuscated payload that harvested cloud, source-control, package-registry, container, Kubernetes, Vault, cryptocurrency, VPN, messaging, and AI-development credentials, with self-propagation functionality.
An external GitHub user abused the package's issue-comment-triggered release workflow, which checked out untrusted pull-request code and used GitHub Actions OIDC trusted publishing, to publish ten malicious @7nohe/openapi-react-query-codegen versions. The stable releases were published in two waves between 20:00:43 and 20:20:53 UTC and included install-time execution mechanisms targeting developer workstations and CI runners.
Researchers reported additional technical details of the malicious payload, including encrypted exfiltration via attacker-created public GitHub repositories, macOS LaunchAgent and Linux systemd-user persistence, signed GitHub commits used as a command channel, and SSH-based propagation attempts. The report also noted that valid npm provenance attestations were present on the malicious releases, while cautioning that behavioral overlap with Mini Shai-Hulud does not establish common-operator attribution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
5 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourceox.security
Open sourcestepsecurity.io
Open sourceaikido.dev
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.