LWA-2026-11683 confirmed malware

@7nohe/openapi-react-query-codegen@0.0.0-365d4eb738d3146583431948d3ba6e27a32556be

Malicious code in @7nohe/openapi-react-query-codegen (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package's preinstall hook (a first-ever install hook on this otherwise legitimate codegen library) downloads the Bun runtime and then attempts to run a script `is_it_this_simple.js` with environment variables WORKFLOW_ID=release.yml, REPO_ID_SUFFIX=7nohe/openapi-react-query-codegen, and TARGET_PACKAGES=@7nohe/openapi-react-query-codegen. This is a GitHub Actions workflow-dispatch attack: the payload is designed to trigger the release.yml workflow on the target repository to publish a malicious version of the package. The referenced script is not bundled in the tarball, so the attack step does not complete, but the install-time hook is malicious and unrelated to the package's code-generation function.

analyzed by
Leitwacht
first seen
Aug 28, 2026, 08:03 PM
analyzed
Aug 28, 2026, 08:04 PM
weekly installs
151,093

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.