Supply Chain Worm Hits Popular TanStack Query Code Generator to Steal Developer Credentials
Brief
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates type-safe TanStack Query hooks, exposing developer and CI systems to credential theft, repository backdoors, and package poisoning.
Aikido Security said it identified 10 malicious versions published within 20 minutes. The package records more than 150,000 weekly downloads, making the incident consequential for developers installing JavaScript dependencies.
The payload identifies itself as “Trinitite: Sponsored by Preview 2 Effects,” and researchers said its tradecraft resembles TeamPCP-linked activity, although attribution remains unresolved.
Supply Chain Worm Hits Popular TanStack Query Code Generator
The compromise reportedly affected both the npm package and its GitHub repository.
