Hostile 92% javascript Download

@7nohe/openapi-react-query-codegen 0.5.4

Malicious binding.gyp and eval dropper

“OpenAPI React Query Codegen”

Python eval escape executes an OS commandnpm binding.gyp Python escape executes command

Also flagged by https://www.aikido.dev/blog/rss.xml (Popular code generator for TanStack Query hit by supply chain worm), https://www.stepsecurity.io/blog/rss.xml (@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow), osm (This legitimate package has been compromised by a threat actor using a GitHub actions worm-like attack.), osv (MAL-2026-15494: Malicious code in @7nohe/openapi-react-query-codegen (npm)) +2 more.

Evidence

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.