@7nohe/openapi-react-query-codegen 1.6.3
binding.gyp executes OS command
“OpenAPI React Query Codegen”
Also flagged by https://www.aikido.dev/blog/rss.xml (Popular code generator for TanStack Query hit by supply chain worm), https://www.stepsecurity.io/blog/rss.xml (@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow), osm (This legitimate package has been compromised by a threat actor using a GitHub actions worm-like attack.), osv (MAL-2026-15494: Malicious code in @7nohe/openapi-react-query-codegen (npm)) +2 more.
Evidence
No evidence locations were recorded for this file. Raw result