OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack: Malicious Versions, GitHub Actions Abuse, Credential Theft and IoCs
29/08/2026-16:23 29/08/2026-16:25 מחשבים וטכנולוגיה CyberSec Guru דיווח
A widely used OpenAPI and React Query code-generation package was compromised in an ongoing npm supply-chain attack, with researchers identifying 10 malicious releases published on August 28, 2026. The compromised package, @7nohe/openapi-react-query-