@7nohe/openapi-react-query-codegen 0.0.0-365d4eb738d3146583431948d3ba6e27a32556be
Shai-Hulud worm preinstall hook
“OpenAPI React Query Codegen”
Preinstall declares Shai-Hulud worm confignpm package executes a high-risk install-time command
SHA-256c555a1ab1a2e0425d6d7f965bae55af83b5aceab2177494a00ec43451c863c63
MaleculeK(Mc)O(S₄)H₃(Db₂F₂Po)Md(Pa₇)
Also flagged by https://www.aikido.dev/blog/rss.xml (Popular code generator for TanStack Query hit by supply chain worm), https://www.stepsecurity.io/blog/rss.xml (@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow), osv (MAL-2026-15494: Malicious code in @7nohe/openapi-react-query-codegen (npm)) +3 more.
Evidence
No evidence locations were recorded for this file. Raw result