A supply-chain worm has compromised a number of releases of @7nohe/openapi-react-query-codegen, an npm package deal that generates type-safe TanStack Question hooks.
Aikido Safety mentioned it recognized 10 malicious variations revealed inside 20 minutes. As a result of the package deal information greater than 150,000 weekly downloads, the incident poses publicity threat to improvement groups.
The breach exposes developer workstations and CI techniques to credential theft, repository backdoors, and secondary package deal poisoning, remodeling a routine JavaScript dependency set up right into a doubtlessly enterprise-wide compromise occasion throughout environments.
Hackers Compromise TanStack Question npm Bundle
Researchers dubbed the payload “Trinitite: Sponsored by Preview 2 Results” and mentioned its tradecraft resembles TeamPCP-linked exercise, though attribution stays unresolved.
The compromise affected npm and the venture’s GitHub repository. Attackers are believed to have exploited a weak spot in a GitHub Actions workflow, permitting malicious releases to retain provenance attestations.
That distinction issues: provenance demonstrates an artifact originated from an permitted workflow, however can not set up that the workflow was unmodified or reliable.

Most weaponized variations used binding.gyp, a Node.js native-addon construct configuration file. Throughout set up, node-gyp evaluates situations by way of Python.
The malicious configuration abuses Python’s class hierarchy to find catch_warnings, get better built-in capabilities, import os, and execute an obfuscated Node.js payload. No native construct happens; the file capabilities as an installation-time execution set off.
Some prerelease builds relied on specific preinstall scripts, whereas later variations mixed each methods. The payload, 3FWCvzduYZg.js, is a 5.4 MB single-line file protected by XOR, AES-GCM, and JavaScript obfuscation.
It silently downloads the Bun runtime earlier than launching credential-harvesting routines, complicating evaluate and turning dependency set up into the execution stage.
The malware checks for Russian locale settings, directories, scanner decoy credentials, analysis accounts, and StepSecurity’s harden-runner, exiting when it detects evaluation situations.
It targets tokens for GitHub, npm, PyPI, and RubyGems, in addition to AWS, Azure, Google Cloud, and HashiCorp Vault credentials. Kubernetes, SSH, Git, VPN, and Claude AI recordsdata are sought. Aikido mentioned the malware can question cloud metadata companies and validate cloud credentials earlier than exfiltration.
Collected data is encrypted, then dedicated to GitHub repositories named after Touhou Challenge characters and labeled with the Trinitite description. This use of repositories provides operators a group endpoint mixing credential theft with infrastructure.
The worm can reuse publishing tokens to inject recordsdata into packages on npm, PyPI, and RubyGems. GitHub tokens could allow repository poisoning by way of backdoored VS Code duties, Claude Code hooks, faux CodeQL workflows, or configuration recordsdata for developer instruments.
Such propagation turns one compromised setting into mechanism infecting initiatives and ecosystems. Organizations ought to establish installations of releases, revoke and rotate credentials on techniques that ran npm set up, and examine repositories for commits or recordsdata.
Groups ought to evaluate GitHub Actions workflows, pin dependencies, and limit publishing tokens. Provenance is efficacious, however it’s an assurance layer, not proof {that a} construct pipeline stays uncompromised.
IOCs
| IOC Kind | Indicator | Description |
|---|---|---|
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious payload file | 3FWCvzduYZg.js |
Obfuscated Node.js credential harvester and worm payload positioned within the package deal root |
| SHA-256 | 8e5d1af68ca340ae0c6e8132cb00c686ec2d60502c1994d94ce353d1472ad5a3 |
Recognized malicious package deal or payload hash |
Word: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintentional decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms equivalent to MISP, VirusTotal, or your SIEM.
Stop incidents resulting from gradual investigations. Energy your Tier 1 with menace intelligence from 15K SOCs: Combine TI Lookup in your SOC









