{"id":18262,"date":"2026-08-30T19:26:00","date_gmt":"2026-08-30T19:26:00","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=18262"},"modified":"2026-08-30T19:26:00","modified_gmt":"2026-08-30T19:26:00","slug":"hackers-compromise-tanstack-question-npm-bundle-to-steal-developer-credentials","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=18262","title":{"rendered":"Hackers Compromise TanStack Question npm Bundle to Steal Developer Credentials"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">A supply-chain worm has compromised a number of releases of <code>@7nohe\/openapi-react-query-codegen<\/code>, an npm package deal that generates type-safe TanStack Question hooks. <\/p>\n<p class=\"wp-block-paragraph\">Aikido Safety mentioned it recognized 10 malicious variations printed inside 20 minutes. As a result of the package deal information greater than 150,000 weekly downloads, the incident poses publicity threat to improvement groups. <\/p>\n<p class=\"wp-block-paragraph\">The breach exposes developer workstations and CI methods to credential theft, repository backdoors, and secondary package deal poisoning, reworking a routine JavaScript dependency set up right into a probably enterprise-wide compromise occasion throughout environments.<\/p>\n<h2 id=\"h-hackers-compromise-tanstack-query-npm-package\" class=\"wp-block-heading\"><strong>Hackers Compromise TanStack Question npm Bundle<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Researchers dubbed the payload \u201cTrinitite: Sponsored by Preview 2 Results\u201d and mentioned its tradecraft resembles TeamPCP-linked exercise, though attribution stays unresolved.<\/p>\n<p class=\"wp-block-paragraph\">The compromise affected npm and the challenge\u2019s GitHub repository. Attackers are believed to have exploited a weak spot in a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/github-actions-abused\/\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub Actions workflow<\/a>, permitting malicious releases to retain provenance attestations. <\/p>\n<p class=\"wp-block-paragraph\">That distinction issues: provenance demonstrates an artifact originated from an accepted workflow, however can&#8217;t set up that the workflow was unmodified or reliable.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi5eZ1IsLqZjiYz77ddb2R4dyEVt-opmRa0j6PU3-cWOqvjIJZ4h4g2r4GoSK3ASegeyLqP_mgM9EwIgpHb8hyphenhyphenqQ1Y30qXL_l81tMpQDFhbS-QoRp28AjStgTLDLjC13Z8i2BgTC4FgrMuPjYeoNtGN4yRYuxoaCZ_HOUBVUgRWv5WIXC0GRE6C3n-Ckyw\/s2876\/hackers-compromise-tanstack-query-npm-package-to-steal-developer-credentials2-6a9296fd34585.webp\" alt=\"exfiltration repos (Source: Aikido)\"\/><figcaption class=\"wp-element-caption\">Exfiltration repos (Supply: Aikido)<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Most weaponized variations used <code>binding.gyp<\/code>, a Node.js native-addon construct configuration file. Throughout set up, <code>node-gyp<\/code> evaluates circumstances by means of Python. <\/p>\n<p class=\"wp-block-paragraph\">The malicious configuration abuses Python\u2019s class hierarchy to find <code>catch_warnings<\/code>, get well built-in features, import <code>os<\/code>, and execute an obfuscated Node.js payload. No native construct happens; the file features as an installation-time execution set off.<\/p>\n<p class=\"wp-block-paragraph\">Some prerelease builds relied on specific <code>preinstall<\/code> scripts, whereas later variations mixed each methods. The payload, <code>3FWCvzduYZg.js<\/code>, is a 5.4 MB single-line file protected by XOR, AES-GCM, and JavaScript obfuscation. <\/p>\n<p class=\"wp-block-paragraph\">It silently downloads the Bun runtime earlier than launching credential-harvesting routines, complicating evaluate and turning dependency set up into the execution stage.<\/p>\n<p class=\"wp-block-paragraph\">The malware checks for Russian locale settings, directories, scanner decoy credentials, analysis accounts, and StepSecurity\u2019s <code>harden-runner<\/code>, exiting when it detects evaluation circumstances. <\/p>\n<p class=\"wp-block-paragraph\">It targets tokens for GitHub, npm, PyPI, and RubyGems, in addition to AWS, Azure, Google Cloud, and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/hashicorp-vault-flaw-allows-login-without-authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">HashiCorp Vault credentials<\/a>. Kubernetes, SSH, Git, VPN, and Claude AI information are sought. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.aikido.dev\/blog\/popular-code-generator-for-tanstack-query-hit-by-supply-chain-worm\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Aikido mentioned the<\/a> malware can question cloud metadata companies and validate cloud credentials earlier than exfiltration. <\/p>\n<p class=\"wp-block-paragraph\">Collected info is encrypted, then dedicated to GitHub repositories named after Touhou Undertaking characters and labeled with the Trinitite description. This use of repositories offers operators a set endpoint mixing credential theft with infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">The worm can reuse publishing tokens to inject information into packages on npm, PyPI, and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/136-malicious-rubygems-packages\/\" target=\"_blank\" rel=\"noreferrer noopener\">RubyGems<\/a>. GitHub tokens could allow repository poisoning by means of backdoored VS Code duties, Claude Code hooks,<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/codeqleaked-github-supply-chain-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\"> pretend CodeQL workflows<\/a>, or configuration information for developer instruments. <\/p>\n<p class=\"wp-block-paragraph\">Such propagation turns one compromised surroundings into mechanism infecting tasks and ecosystems. Organizations ought to establish installations of releases, revoke and rotate credentials on methods that ran <code>npm set up<\/code>, and examine repositories for commits or information. <\/p>\n<p class=\"wp-block-paragraph\">Groups ought to evaluate GitHub Actions workflows, pin dependencies, and limit publishing tokens. Provenance is effective, however it&#8217;s an assurance layer, not proof {that a} construct pipeline stays uncompromised.<\/p>\n<p class=\"wp-block-paragraph\"><strong>IOCs<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">IOC Kind<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious npm package deal<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>@7nohe\/<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"375847525956475e1a45525654431a464252454e1a54585352505259770719021903\">[email\u00a0protected]<\/a><\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Confirmed compromised launch<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious npm package deal<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>@7nohe\/<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"204f50454e4150490d52454143540d51554552590d434f444547454e60100e150e15\">[email\u00a0protected]<\/a><\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Confirmed compromised launch<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious npm package deal<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>@7nohe\/<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"7f100f1a111e0f16520d1a1e1c0b520e0a1a0d06521c101b1a181a113f4e5149514c\">[email\u00a0protected]<\/a><\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Confirmed compromised launch<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious npm package deal<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>@7nohe\/<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"244b54414a45544d09564145475009555141565d09474b404143414a64150a120a10\">[email\u00a0protected]<\/a><\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Confirmed compromised launch<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious npm package deal<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>@7nohe\/<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"cba4bbaea5aabba2e6b9aeaaa8bfe6babeaeb9b2e6a8a4afaeacaea58bf9e5f9e5fa\">[email\u00a0protected]<\/a><\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Confirmed compromised launch<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious npm package deal<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>@7nohe\/<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"cda2bda8a3acbda4e0bfa8acaeb9e0bcb8a8bfb4e0aea2a9a8aaa8a38dffe3ffe3ff\">[email\u00a0protected]<\/a><\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Confirmed compromised launch<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious npm package deal<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>@7nohe\/<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"f69986939897869fdb8493979582db878393848fdb95999293919398b6c5d8c6d8c5\">[email\u00a0protected]<\/a><\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Confirmed compromised launch<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious npm package deal<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>@7nohe\/<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"177867727976677e3a65727674633a666272656e3a74787372707279572439273923\">[email\u00a0protected]<\/a><\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Confirmed compromised launch<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious payload file<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>3FWCvzduYZg.js<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Obfuscated Node.js credential harvester and worm payload positioned within the package deal root<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>8e5d1af68ca340ae0c6e8132cb00c686ec2d60502c1994d94ce353d1472ad5a3<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Recognized malicious package deal or payload hash<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Be aware:<\/strong>\u00a0<em>IP addresses and domains are deliberately defanged (e.g.,\u00a0<\/em><code><em>[.]<\/em><\/code><em>) to stop unintended decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms resembling MISP, VirusTotal, or your SIEM<\/em>.\u00a0<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong><strong>Stop incidents as a result of sluggish investigations. Energy your Tier 1 with menace intelligence from 15K SOCs:\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=csn&amp;utm_medium=100+links&amp;utm_campaign=lookup+tier+1&amp;utm_content=ti+lookup+sales&amp;utm_term=190826#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Combine TI\u00a0Lookup in\u00a0your SOC<\/a><\/strong><\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A supply-chain worm has compromised a number of releases of @7nohe\/openapi-react-query-codegen, an npm package deal that generates type-safe TanStack Question hooks. Aikido Safety mentioned it recognized 10 malicious variations printed inside 20 minutes. As a result of the package deal information greater than 150,000 weekly downloads, the incident poses publicity threat to improvement groups. The [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":18264,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1429,483,1217,554,1116,1717,7909,1443,9148],"class_list":["post-18262","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-compromise","tag-credentials","tag-developer","tag-hackers","tag-npm","tag-package","tag-query","tag-steal","tag-tanstack"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18262","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18262"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18262\/revisions"}],"predecessor-version":[{"id":18263,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18262\/revisions\/18263"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/18264"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}