<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/openapi-react-query-codegen-compromised-in-mini-shai-hulud-npm-supply-chain-attack-aar0hqr8j" -->

---
title: OpenAPI React Query Codegen Compromised in Mini...
description: Ten malicious versions of the npm package @7nohe/openapi-react-query-codegen were published on August 28, 2026, in a Mini Shai-Hulud supply chain attack. The...
canonical: https://daily.dev/posts/openapi-react-query-codegen-compromised-in-mini-shai-hulud-npm-supply-chain-attack-aar0hqr8j
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack | daily.dev
og:description: Ten malicious versions of the npm package @7nohe/openapi-react-query-codegen were published on August 28, 2026, in a Mini Shai-Hulud supply chain attack. The...
og:url: https://daily.dev/posts/openapi-react-query-codegen-compromised-in-mini-shai-hulud-npm-supply-chain-attack-aar0hqr8j
og:image: https://api.daily.dev/og/posts/aaR0hqr8J.png
og:image:alt: OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

**[Socket](https://daily.dev/sources/socketdev)** · 7 min read · 1 upvotes · 0 comments

## Summary

Ten malicious versions of the npm package @7nohe/openapi-react-query-codegen were published on August 28, 2026, in a Mini Shai-Hulud supply chain attack. The attacker exploited a comment-triggered GitHub Actions publishing workflow (triggered by commenting 'npm publish' on any pull request) to publish attacker-controlled code from a fork under the repository's trusted OIDC identity, producing valid npm provenance attestations despite the tarballs containing malware. The malicious code, delivered via binding.gyp or preinstall scripts, decrypts and runs a second-stage payload targeting cloud credentials, npm/GitHub tokens, and AI agent configs, with self-propagation behavior. At the time of writing, the npm 'latest' tag still resolved to a compromised version (3.0.4); known-good versions are 0.5.3, 1.6.2, 2.2.0, and 3.0.2. The report stresses that npm provenance and 'npm audit signatures' do not detect this attack since the workflow itself was legitimate but abused.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://socket.dev/blog/openapi-react-query-codegen-npm-compromise>

## Questions this post answers

### Which versions of @7nohe/openapi-react-query-codegen are compromised and which are safe to use?

Ten versions are malicious: two 0.0.0 prereleases, 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, and 3.0.4, published on August 28, 2026 in the Mini Shai-Hulud attack. The npm 'latest' tag resolved to malicious 3.0.4 at the time of the report. Known-good versions to pin are 0.5.3, 1.6.2, 2.2.0, and 3.0.2.

_Track fast-moving npm supply chain incidents like this one on daily.dev before pinning dependency versions._

### Why doesn't npm audit signatures or provenance verification catch a compromised package published through a legitimate GitHub Actions workflow?

Because provenance only proves which workflow built the artifact, not that the workflow only builds trusted source. In this attack, a comment-triggered publish workflow (issue_comment on 'npm publish') checked out an untrusted fork's pull request head and published it under the repository's legitimate OIDC identity, so the resulting SLSA attestations pointed to the clean main branch commit while the tarball contained attacker code, passing npm audit signatures.

_Developers hardening CI/CD publishing pipelines can follow supply chain security coverage on daily.dev._

### How can maintainers prevent a comment-triggered npm publish GitHub Actions workflow from being abused by an untrusted fork?

Verify the commenter's repository association using github.event.comment.author_association before running any job with id-token: write permissions, or switch the publish trigger to something that cannot be fired by an untrusted account. Without that check, any GitHub account can post 'npm publish' on a pull request comment and have the workflow check out and publish the fork's code under the repository's trusted publishing identity.

_Maintainers securing release workflows can find similar CI/CD hardening guidance on daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#github-actions](https://daily.dev/tags/github-actions), [#npm](https://daily.dev/tags/npm), [#react-query](https://daily.dev/tags/react-query)

[View this post on daily.dev](https://daily.dev/posts/openapi-react-query-codegen-compromised-in-mini-shai-hulud-npm-supply-chain-attack-aar0hqr8j)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack","url":"https://daily.dev/posts/openapi-react-query-codegen-compromised-in-mini-shai-hulud-npm-supply-chain-attack-aar0hqr8j","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/openapi-react-query-codegen-compromised-in-mini-shai-hulud-npm-supply-chain-attack-aar0hqr8j"},"datePublished":"2026-08-28T22:53:19.069Z","dateModified":"2026-08-28T23:21:07.153Z","description":"Ten malicious versions of the npm package @7nohe/openapi-react-query-codegen were published on August 28, 2026, in a Mini Shai-Hulud supply chain attack. The...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d0853ccb8b9ee109640414222d425c3c?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d0853ccb8b9ee109640414222d425c3c?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Socket","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Socket","logo":"https://media.daily.dev/image/upload/s---oEn9czC--/f_auto/v1716187892/logos/socketdev","url":"https://daily.dev/sources/socketdev"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/openapi-react-query-codegen-compromised-in-mini-shai-hulud-npm-supply-chain-attack-aar0hqr8j","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,github-actions,npm,react-query","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Socket","item":"https://daily.dev/sources/socketdev"},{"@type":"ListItem","position":3,"name":"OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/openapi-react-query-codegen-compromised-in-mini-shai-hulud-npm-supply-chain-attack-aar0hqr8j#faq","mainEntity":[{"@type":"Question","name":"Which versions of @7nohe/openapi-react-query-codegen are compromised and which are safe to use?","acceptedAnswer":{"@type":"Answer","text":"Ten versions are malicious: two 0.0.0 prereleases, 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, and 3.0.4, published on August 28, 2026 in the Mini Shai-Hulud attack. The npm 'latest' tag resolved to malicious 3.0.4 at the time of the report. Known-good versions to pin are 0.5.3, 1.6.2, 2.2.0, and 3.0.2. Track fast-moving npm supply chain incidents like this one on daily.dev before pinning dependency versions."}},{"@type":"Question","name":"Why doesn't npm audit signatures or provenance verification catch a compromised package published through a legitimate GitHub Actions workflow?","acceptedAnswer":{"@type":"Answer","text":"Because provenance only proves which workflow built the artifact, not that the workflow only builds trusted source. In this attack, a comment-triggered publish workflow (issue_comment on 'npm publish') checked out an untrusted fork's pull request head and published it under the repository's legitimate OIDC identity, so the resulting SLSA attestations pointed to the clean main branch commit while the tarball contained attacker code, passing npm audit signatures. Developers hardening CI/CD publishing pipelines can follow supply chain security coverage on daily.dev."}},{"@type":"Question","name":"How can maintainers prevent a comment-triggered npm publish GitHub Actions workflow from being abused by an untrusted fork?","acceptedAnswer":{"@type":"Answer","text":"Verify the commenter's repository association using github.event.comment.author_association before running any job with id-token: write permissions, or switch the publish trigger to something that cannot be fired by an untrusted account. Without that check, any GitHub account can post 'npm publish' on a pull request comment and have the workflow check out and publish the fork's code under the repository's trusted publishing identity. Maintainers securing release workflows can find similar CI/CD hardening guidance on daily.dev."}}]}
```

