advisory-catalog: openapi-react-query-codegen-2026-08-28 - #77
Draft
ronheichman wants to merge 1 commit into
Draft
Conversation
…Hulud npm compromise catalog Ten malicious versions of @7nohe/openapi-react-query-codegen were published on 2026-08-28 in two waves across every maintained release line via a comment-triggered GitHub Actions publishing workflow. The malicious releases execute an obfuscated bundled loader at install time via binding.gyp / preinstall, targeting cloud, npm, GitHub Actions, and AI agent secrets, with self-propagation. Source: https://socket.dev/blog/openapi-react-query-codegen-npm-compromise Corroboration: npm registry publication timestamps (2026-08-28T20:00Z-20:20Z) and deps.dev.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a Bumblebee threat_intel catalog for the Mini Shai-Hulud npm supply-chain compromise of
@7nohe/openapi-react-query-codegen, reported by Socket on 2026-08-28.Source: https://socket.dev/blog/openapi-react-query-codegen-npm-compromise (
date_published: 2026-08-28T20:49:35Z)Compromised versions (10):
0.0.0-365d4eb738d3146583431948d3ba6e27a32556be0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab0.5.4,0.5.51.6.3,1.6.42.2.1,2.2.23.0.3,3.0.4Last known-good version per release line:
0.5.3,1.6.2,2.2.0,3.0.2.Public corroboration (two non-origin sources):
https://registry.npmjs.org/@7nohe/openapi-react-query-codegen: all 10 versions present with publication timestamps2026-08-28T20:00Z-20:20Z, matching Socket's two-wave timing.https://api.deps.dev/v3/systems/npm/packages/%407nohe%2Fopenapi-react-query-codegen/versions/<v>: confirms the same publication timestamps for the 3.0.4 / 2.2.2 / 1.6.4 / 0.5.5 wave-2 versions (spot-checked).OSV (
api.osv.dev/v1/queryon npm) and the GitHub Advisory Database (GET /advisories?ecosystem=npm&type=malware) had no entries for this package at the time of cataloging; expected to populate as MAL-/GHSA- ids are issued. This will not delay publication given the strong registry-side corroboration.Yank observation: none — all 10 malicious versions were still installable at the time of the Socket post and at the time of cataloging.
Ecosystem-enum note: none —
npmis in the schema enum, and the catalog usesentries[]as normal (no_<ecosystem>_packagesfallback needed).Dropped items: none — every
(ecosystem, package, version)claim in the Socket post is present inentries[0].versions.Root cause per Socket (not encoded in this catalog):
release.ymltriggered onissue_comment: [created]and gated only on comment text; any GitHub account could publish a fork's contents under the repo's trusted-publishing identity by commentingnpm publishon any pull request. All ten malicious versions carry valid npm provenance attestations, sonpm audit signatureswill not flag them.Bumblebee scan-time exposure check: exact
(ecosystem, package, version)presence match against on-disk manifests / lockfiles. Not intended to check network/file/process IOCs.