Summary
A new Shai-Hulud malware variant called Trinitite compromised the @7nohe/openapi-react-query-codegen npm package, affecting over 128,000 weekly downloads. The malware steals high-value cloud and registry credentials and exfiltrates them to GitHub repositories using automated propagation techniques.
Take Action:
If you installed @7nohe/openapi-react-query-codegen on 28–29 August 2026 (versions 0.5.4/0.5.5, 1.6.3/1.6.4, 2.2.1/2.2.2, or 3.0.3/3.0.4), treat that machine or CI runner as fully compromised: rotate every credential it could reach: GitHub, npm, cloud keys, SSH keys, tokens. Also, turn on 2FA everywhere. Then pin the package to a specific known-good version published before 20:19 UTC on 28 August 2026 and verify its hash.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)