Shai-Hulud Trinitite Hits @7nohe/openapi-react-query-codegen
A new Mini Shai-Hulud worm variant named Trinitite was detected on August 28, 2026, targeting the npm package @7nohe/openapi-react-query-codegen, a TanStack Query codegen tool with over 150K weekly downloads. The attacker exploited a workflow vulnerability that allowed any GitHub user to trigger npm publish via pull-request comments, publishing ten malicious versions in twenty minutes. The worm uses XOR-wrapped loaders and obfuscated binding.gyp files to execute even when scripts are disabled. It steals credentials from GitHub, npm, PyPI, RubyGems, cloud services, Vault, and Kubernetes, exfiltrating data via GitHub commits. The malware establishes persistence through systemd services and includes a token revoke trap that can wipe user directories. This campaign appeared shortly after TeamPCP suspects were arrested in Australia, using the same toolkit but with new RSA keys and graffiti.
Indicators of Compromise
- hash: 365d4eb738d3146583431948d3ba6e27a32556be
- hash: ec7876d6c917dad516ba69bbfafc948b834bf0ab
- domain: poopy.com
- hash: 043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
Shai-Hulud Trinitite Hits @7nohe/openapi-react-query-codegen
Description
A new Mini Shai-Hulud worm variant named Trinitite was detected on August 28, 2026, targeting the npm package @7nohe/openapi-react-query-codegen, a TanStack Query codegen tool with over 150K weekly downloads. The attacker exploited a workflow vulnerability that allowed any GitHub user to trigger npm publish via pull-request comments, publishing ten malicious versions in twenty minutes. The worm uses XOR-wrapped loaders and obfuscated binding.gyp files to execute even when scripts are disabled. It steals credentials from GitHub, npm, PyPI, RubyGems, cloud services, Vault, and Kubernetes, exfiltrating data via GitHub commits. The malware establishes persistence through systemd services and includes a token revoke trap that can wipe user directories. This campaign appeared shortly after TeamPCP suspects were arrested in Australia, using the same toolkit but with new RSA keys and graffiti.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://research.jfrog.com/post/shai-hulud-trinitite"]
- Adversary
- TeamPCP
- Pulse Id
- 6a959d3149cc19143a799af6
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash365d4eb738d3146583431948d3ba6e27a32556be | — | |
hashec7876d6c917dad516ba69bbfafc948b834bf0ab | — | |
hash043fb46d1a93c77aae656e7c1c64a875d1fc6a0a | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainpoopy.com | — |
Threat ID: 6a968ebbacd9273b49712961
Added to database: 09/01/2026, 08:37:15 UTC
Last updated: 09/01/2026, 12:52:52 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.