@7nohe/openapi-react-query-codegen npm Package Compromised
- Severity
- HIGH
- Affected component
- @7nohe/openapi-react-query-codegen (npm)
- Affected versions
- >= 3.0.4, <= 3.0.4 or >= 1.6.3, <= 1.6.3 or >= 3.0.3, <= 3.0.3 or >= 0.5.4, <= 0.5.4 or >= 0.5.5, <= 0.5.5 or >= 2.2.1, <= 2.2.1 or >= 2.2.2, <= 2.2.2 or >= 1.6.4, <= 1.6.4 or >= 0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab, <= 0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab or >= 0.0.0-365d4eb738d3146583431948d3ba6e27a32556be, <= 0.0.0-365d4eb738d3146583431948d3ba6e27a32556be
- Patched version
- Not yet available
An external attacker exploited an exposed npm publishing workflow for @7nohe/openapi-react-query-codegen and published ten malicious versions. Users of this package are potentially affected.
What happened
On August 28, 2026, an external GitHub user exploited the release workflow for @7nohe/openapi-react-query-codegen and published ten malicious npm versions. The affected releases execute attacker-supplied code during installation. The eight stable releases used a malicious binding.gyp path, an explicit preinstall hook, or both. Direct execution of the payload from version 3.0.4 attempted to retrieve GitHub credentials, contacted the GitHub API, and probed the Google Cloud metadata hostname.
The attacker did not need a maintainer npm password or a long-lived npm token. The repository accepted an npm publish comment from any pull request participant, checked out that pull request, installed its dependencies, and published packages with a GitHub Actions OIDC identity. StepSecurity reproduced the installation behavior on isolated GitHub-hosted runners under Harden-Runner.
What to do about it
- Review your dependencies for @7nohe/openapi-react-query-codegen and remove any affected versions.
- Avoid installing @7nohe/openapi-react-query-codegen@latest as npm still mapped latest to malicious version 3.0.4 at the time of publication.
- If an affected version ran installation scripts, isolate the system and rotate accessible credentials from a separate clean machine.
- Monitor the primary sources for updates on patched versions and further recovery steps.
- Consult the provided IOCs and recovery steps from the primary sources.
How 0Day would have caught this
@7nohe/openapi-react-query-codegen is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using @7nohe/openapi-react-query-codegen in the version ranges >= 3.0.4, <= 3.0.4 or >= 1.6.3, <= 1.6.3 or >= 3.0.3, <= 3.0.3 or >= 0.5.4, <= 0.5.4 or >= 0.5.5, <= 0.5.5 or >= 2.2.1, <= 2.2.1 or >= 2.2.2, <= 2.2.2 or >= 1.6.4, <= 1.6.4 or >= 0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab, <= 0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab or >= 0.0.0-365d4eb738d3146583431948d3ba6e27a32556be, <= 0.0.0-365d4eb738d3146583431948d3ba6e27a32556be.
What should I do right now?
Review your dependencies for @7nohe/openapi-react-query-codegen and remove any affected versions. Avoid installing @7nohe/openapi-react-query-codegen@latest as npm still mapped latest to malicious version 3.0.4 at the time of publication. If an affected version ran installation scripts, isolate the system and rotate accessible credentials from a separate clean machine. Monitor the primary sources for updates on patched versions and further recovery steps.
Has this been exploited in the wild?
No, this threat has not been exploited in the wild according to the primary sources.