logo

Popular code generator for TanStack Query hit by supply chain worm

ID: b23ea17a-dcf3-59ae-af83-27ef6e86a516

STIX ID: report--b23ea17a-dcf3-59ae-af83-27ef6e86a516

Feed Name: Aikido Security's Blog

Threat Score
90/100

Date Published: 2026-08-28

Date Updated: 2026-08-29

...
...

Trinitite is an active supply-chain malware campaign that injected malicious code into ten versions of the npm package @7nohe/openapi-react-query-codegen (high download volume). The attackers used a GitHub Actions workflow compromise and a Python sandbox escape in binding.gyp to execute an obfuscated JavaScript payload that harvests extensive credentials (cloud providers, developer tokens, keys, wallets and local files), exfiltrates data to public GitHub repositories as encrypted blobs, and self-propagates by publishing backdoored releases to npm/PyPI/RubyGems and committing backdoors to accessible GitHub repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.