← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 28, 2026 · 20:49via Socket Security Blog

OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

Brief

Ten malicious versions were published with valid npm provenance after a threat actor abused a comment-triggered GitHub Actions publishing workflow, with the latest release still compromised at the time of writing. The Socket Threat Research Team is investigating an ongoing Mini Shai-Hulud compromise, affecting the npm package @7nohe/openapi-react-query-codegen .

On August 28, 2026, ten malicious versions were published in two waves roughly twenty minutes apart, spanning every maintained release line. At the time of writing, all ten remain installable and the latest tag resolves to malicious version 3.

  • 4 . The package receives roughly 1 50,000 weekly downloads across all versions.

The compromised releases execute threat actor-controlled code during installation.

Read more on Socket Security Blog