Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Real-time Open Source Software Supply Chain Security

0
Medium
Published: 08/31/2026 (08/31/2026, 09:00:33 UTC)
Source: AlienVault OTX General

Description

On August 28, 2026, an attacker published 10 malicious versions of the npm package @7nohe/openapi-react-query-codegen by exploiting a flawed GitHub Actions workflow. The release pipeline contained an issue_comment trigger without author-association gates, allowing any GitHub user to trigger npm publishing from a forked repository. The attacker opened pull requests from a fork and used an npm publish comment to execute their code with OIDC token minting permissions. The payload employed dual execution triggers: a binding.gyp file exploiting node-gyp's Python evaluation to execute commands, and a preinstall hook. The main payload, 3FWCvzduYZg.js, was a multi-megabyte obfuscated script with three decryption layers leading to a bootstrapper that downloaded Bun v1.4.0. This attack pattern matches the Mini Shai-Hulud toolkit previously used in SAP and AntV compromises. All malicious versions were removed from npm.

Technical Details

Author
AlienVault
Tlp
white
References
["https://safedep.io/mini-shai-hulud-openapi-react-query-codegen-compromised/"]
Adversary
Mini Shai-Hulud
Pulse Id
6a9542b1777be9247d2c6ded
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashb24d121667f21f492cb9db34fbfd515d5922a8dd30b9c45215c7220abbb10ca8
hashb49afb7dba04cd99b357ce7c652c823a3707f28e130bd5c6645851a7adc030d6
hash59370c67b54a0ccaedd265e2356f04540b2fba1e1845300ef6de4d5437d99380
hashd3246926b20a8d021ed7de0ac8e9eee1dda986088f84ba18f31cb2042a121f5d
hash365d4eb738d3146583431948d3ba6e27a32556be
hashec7876d6c917dad516ba69bbfafc948b834bf0ab
hash0d58f3434c55842fc41ad99656c20a295d46e7d16f432a122a5a094d7c1de0e2
hash1757c9203143db4958b53cb5c97af64bfe46ad57a07764fed59bbb886a71f1da
hash5654e2b3e19cf5e7f1d39d04ebdd3507d3349f76eeb8319de42b2fdb537b8a2d
hash709af2fdeb50324229e94c44c679a0fab18bd8e17d3864405989c526cbb63ad8
hash73bac41332ea7438b671e6538750502a4548302ce26f99e114ded478436a0cb4
hash778d6f0058045d6a2ab9a7e1d3e3be8e7e6b4d9cc217d13949bf1dfbab759a7c
hash8e5d1af68ca340ae0c6e8132cb00c686ec2d60502c1994d94ce353d1472ad5a3
hasha8c00f59e629e5bc4fc6a116fa1ceb8fcf328893a9c798ca446fdcacb0fbdc18
hashacaee3a02873334002a27d6643c20f4e38e52c8d0d1f492788e2b68586e2cbfa
hashb6012b2ff87f08f93ee53921c48db907ddbcf5461b03bb988083b01a36886237
hashc555a1ab1a2e0425d6d7f965bae55af83b5aceab2177494a00ec43451c863c63
hashcb46dbd078753f562931920fe4b109c673925138b0e9399527e84c53f07d8a7a
hashd1f9960349f2bc0689518ef754d577e1c13125db59b0252f1c85894bb69b5c8e
hashe1f1162ece9a6e6ea21a20399cbf31c563a8149d433a68711f4223870c203d5a
hashf2f88ce6e8b0d8a6c75b4c6cf6a23db4bc1430f359b9bb12c9418fcb74cdfe46

Threat ID: 6a954b4eacd9273b49e06edb

Added to database: 08/31/2026, 09:37:18 UTC

Last updated: 08/31/2026, 11:52:39 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses