logo

Shai-Hulud Trinitite Worm Infects Popular TanStack Query npm Package to Steal Developer Secrets

ID: e6cd1868-7064-5a31-8df6-d73647d4be98

STIX ID: report--e6cd1868-7064-5a31-8df6-d73647d4be98

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

Author: Mayura Kathir

...
...

Trinitite is a supply-chain worm that compromised the npm package @7nohe/openapi-react-query-codegen to steal a wide range of credentials and propagate by abusing GitHub Actions release workflows and npm publishing; the malware leverages a malicious binding.gyp evaluated by node-gyp (bypassing npm lifecycle-script inspection), an XOR-obfuscated loader, strong encryption, and persistence that can attempt destructive cleanup when tokens are revoked. Affected versions and IOCs are listed and the report urges isolating infected hosts/runners, removing persistence, regenerating lockfiles, pinning to safe releases, and rotating exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.