Embedded Malicious Code Affecting @7nohe/openapi-react-query-codegen package, versions =0.5.4=0.5.5=1.6.3=1.6.4=2.2.1=2.2.2=3.0.3=3.0.4=0.0.0-365d4eb738d3146583431948d3ba6e27a32556be=0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-7NOHEOPENAPIREACTQUERYCODEGEN-19424702
  • published28 Aug 2026
  • disclosed28 Aug 2026
  • creditUnknown

Introduced: 28 Aug 2026

New Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the @7nohe/openapi-react-query-codegen package.

Overview

@7nohe/openapi-react-query-codegen is an OpenAPI React Query Codegen

Affected versions of this package are vulnerable to Embedded Malicious Code that conceals a destructive worm and credential harvester. A malicious actor exploited a comment-triggered GitHub Actions workflow by commenting on a pull request fork, allowing the attacker to bypass access controls and publish tampered versions of the package to npm, all with valid provenance attestations.

Worm Behavior

The malicious releases use a binding.gyp Python sandbox escape or a preinstall script to silently download the Bun runtime and execute a heavily obfuscated payload. The payload harvests a wide range of sensitive data including cloud credentials (AWS, Azure, GCP), developer tokens (npm, PyPI, RubyGems), and local SSH keys. It exfiltrates this data by using stolen tokens to automatically create public GitHub repositories that store the encrypted credentials.

Notes:

  • The execution is triggered natively during installation via node-gyp processing or standard preinstall hooks, meaning developer environments and CI runners are immediately targeted on npm install.

  • Despite being malicious, the compromised versions will pass npm audit signatures because they carry valid cryptographic npm provenance attestations generated by the hijacked GitHub workflow.

  • The malware contains evasion techniques to avoid execution in certain environments, such as security scanners, specific geographic locales, and endpoints running certain security software.

References

CVSS Base Scores

version 4.0
version 3.1