@7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be
Malicious code in @7nohe/openapi-react-query-codegen (npm)
Analysis
The package's preinstall hook (a first-ever install hook on this otherwise legitimate codegen library) downloads the Bun runtime and then attempts to run a script `is_it_this_simple.js` with environment variables WORKFLOW_ID=release.yml, REPO_ID_SUFFIX=7nohe/openapi-react-query-codegen, and TARGET_PACKAGES=@7nohe/openapi-react-query-codegen. This is a GitHub Actions workflow-dispatch attack: the payload is designed to trigger the release.yml workflow on the target repository to publish a malicious version of the package. The referenced script is not bundled in the tarball, so the attack step does not complete, but the install-time hook is malicious and unrelated to the package's code-generation function.
- analyzed by
- Leitwacht
- first seen
- Aug 28, 2026, 08:03 PM
- analyzed
- Aug 28, 2026, 08:04 PM
- weekly installs
- 151,093
Related advisories
- mfa-js@1.0.4
- @bx-ui-framework/common@15.0.0
- 2fasecretkey@1.1.2
- 2fa-secretkey@1.0.1
- discord-mfa@3.0.0
- vitest-chalk-pro@10.0.7
- hydration-ui-dlx@1.0.0
- eth-pino@2.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.