A compromised release of @7nohe/openapi-react-query-codegen runs a dropper on install through three separate triggers, then harvests cloud credentials and republishes itself across npm, RubyGems, and now PyPI. It shipped with valid npm provenance.
Mini Shai-Hulud worm hits openapi-react-query-codegen, spreads across npm, RubyGems, and PyPI | Blog | Endor Labs
calendar_today
August 28, 2026
domain
endor-labs