A supply-chain worm has compromised a number of releases of @7nohe/openapi-react-query-codegen, an npm package deal that generates type-safe TanStack Question hooks.
Aikido Safety mentioned it recognized 10 malicious variations printed inside 20 minutes. As a result of the package deal information greater than 150,000 weekly downloads, the incident poses publicity threat to improvement groups.
The breach exposes developer workstations and CI methods to credential theft, repository backdoors, and secondary package deal poisoning, reworking a routine JavaScript dependency set up right into a probably enterprise-wide compromise occasion throughout environments.
Hackers Compromise TanStack Question npm Bundle
Researchers dubbed the payload “Trinitite: Sponsored by Preview 2 Results” and mentioned its tradecraft resembles TeamPCP-linked exercise, though attribution stays unresolved.
The compromise affected npm and the challenge’s GitHub repository. Attackers are believed to have exploited a weak spot in a GitHub Actions workflow, permitting malicious releases to retain provenance attestations.
That distinction issues: provenance demonstrates an artifact originated from an accepted workflow, however can’t set up that the workflow was unmodified or reliable.
Most weaponized variations used binding.gyp, a Node.js native-addon construct configuration file. Throughout set up, node-gyp evaluates circumstances by means of Python.
The malicious configuration abuses Python’s class hierarchy to find catch_warnings, get well built-in features, import os, and execute an obfuscated Node.js payload. No native construct happens; the file features as an installation-time execution set off.
Some prerelease builds relied on specific preinstall scripts, whereas later variations mixed each methods. The payload, 3FWCvzduYZg.js, is a 5.4 MB single-line file protected by XOR, AES-GCM, and JavaScript obfuscation.
It silently downloads the Bun runtime earlier than launching credential-harvesting routines, complicating evaluate and turning dependency set up into the execution stage.
The malware checks for Russian locale settings, directories, scanner decoy credentials, analysis accounts, and StepSecurity’s harden-runner, exiting when it detects evaluation circumstances.
It targets tokens for GitHub, npm, PyPI, and RubyGems, in addition to AWS, Azure, Google Cloud, and HashiCorp Vault credentials. Kubernetes, SSH, Git, VPN, and Claude AI information are sought. Aikido mentioned the malware can question cloud metadata companies and validate cloud credentials earlier than exfiltration.
Collected info is encrypted, then dedicated to GitHub repositories named after Touhou Undertaking characters and labeled with the Trinitite description. This use of repositories offers operators a set endpoint mixing credential theft with infrastructure.
The worm can reuse publishing tokens to inject information into packages on npm, PyPI, and RubyGems. GitHub tokens could allow repository poisoning by means of backdoored VS Code duties, Claude Code hooks, pretend CodeQL workflows, or configuration information for developer instruments.
Such propagation turns one compromised surroundings into mechanism infecting tasks and ecosystems. Organizations ought to establish installations of releases, revoke and rotate credentials on methods that ran npm set up, and examine repositories for commits or information.
Groups ought to evaluate GitHub Actions workflows, pin dependencies, and limit publishing tokens. Provenance is effective, however it’s an assurance layer, not proof {that a} construct pipeline stays uncompromised.
IOCs
| IOC Kind | Indicator | Description |
|---|---|---|
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious npm package deal | @7nohe/[email protected] |
Confirmed compromised launch |
| Malicious payload file | 3FWCvzduYZg.js |
Obfuscated Node.js credential harvester and worm payload positioned within the package deal root |
| SHA-256 | 8e5d1af68ca340ae0c6e8132cb00c686ec2d60502c1994d94ce353d1472ad5a3 |
Recognized malicious package deal or payload hash |
Be aware: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintended decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms resembling MISP, VirusTotal, or your SIEM.
Stop incidents as a result of sluggish investigations. Energy your Tier 1 with menace intelligence from 15K SOCs: Combine TI Lookup in your SOC






