Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Shai-Hulud Trinitite Hits @7nohe/openapi-react-query-codegen

0
Medium
Published: 08/31/2026 (08/31/2026, 15:26:41 UTC)
Source: AlienVault OTX General

Description

A new Mini Shai-Hulud worm variant named Trinitite was detected on August 28, 2026, targeting the npm package @7nohe/openapi-react-query-codegen, a TanStack Query codegen tool with over 150K weekly downloads. The attacker exploited a workflow vulnerability that allowed any GitHub user to trigger npm publish via pull-request comments, publishing ten malicious versions in twenty minutes. The worm uses XOR-wrapped loaders and obfuscated binding.gyp files to execute even when scripts are disabled. It steals credentials from GitHub, npm, PyPI, RubyGems, cloud services, Vault, and Kubernetes, exfiltrating data via GitHub commits. The malware establishes persistence through systemd services and includes a token revoke trap that can wipe user directories. This campaign appeared shortly after TeamPCP suspects were arrested in Australia, using the same toolkit but with new RSA keys and graffiti.

Technical Details

Author
AlienVault
Tlp
white
References
["https://research.jfrog.com/post/shai-hulud-trinitite"]
Adversary
TeamPCP
Pulse Id
6a959d3149cc19143a799af6
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash365d4eb738d3146583431948d3ba6e27a32556be
hashec7876d6c917dad516ba69bbfafc948b834bf0ab
hash043fb46d1a93c77aae656e7c1c64a875d1fc6a0a

Domain

ValueDescriptionCopy
domainpoopy.com

Threat ID: 6a968ebbacd9273b49712961

Added to database: 09/01/2026, 08:37:15 UTC

Last updated: 09/01/2026, 12:52:52 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses