www.stepsecurity.io 8/28/2026, 11:22:25 PM · external

Compromised npm package leaks GitHub credentials via harmful code

Compromised npm package leaks GitHub credentials via harmful code
CyberSIXT Evidence Panel Source marked as original reporting

ON August 28, 2026, the npm package `@7nohe/openapi-react-query-codegen` was compromised by an external GitHub user, leading to the release of ten malicious versions. The attacker leveraged an exposed npm publishing workflow to execute malicious code during installation, specifically aiming to steal sensitive data like GitHub credentials. Key points include:

View full article

Article by CyberSIXT