How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Mini Shai-Hulud worm hits openapi-react-query-codegen, spreads across npm, RubyGems, and PyPI | Blog | Endor Labs

calendar_today August 28, 2026 domain endor-labs

A compromised release of @7nohe/openapi-react-query-codegen runs a dropper on install through three separate triggers, then harvests cloud credentials and republishes itself across npm, RubyGems, and now PyPI. It shipped with valid npm provenance.

open_in_new Read original post