OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Brief
Ten malicious versions were published with valid npm provenance after a threat actor abused a comment-triggered GitHub Actions publishing workflow, with the latest release still compromised at the time of writing. The Socket Threat Research Team is investigating an ongoing Mini Shai-Hulud compromise, affecting the npm package @7nohe/openapi-react-query-codegen .
On August 28, 2026, ten malicious versions were published in two waves roughly twenty minutes apart, spanning every maintained release line. At the time of writing, all ten remain installable and the latest tag resolves to malicious version 3.
- 4 . The package receives roughly 1 50,000 weekly downloads across all versions.
The compromised releases execute threat actor-controlled code during installation.
