ON August 28, 2026, the npm package `@7nohe/openapi-react-query-codegen` was compromised by an external GitHub user, leading to the release of ten malicious versions. The attacker leveraged an exposed npm publishing workflow to execute malicious code during installation, specifically aiming to steal sensitive data like GitHub credentials. Key points include:
- **Compromised Versions**: Versions affected include multiple stable releases (e.g., 3.0.4), which contained malicious `preinstall` hooks and obfuscated payloads.
- **Exploitation Method**: The attacker exploited the package's release workflow that allowed unverified `npm publish` comments from any pull request participant, enabling malicious code publishing.
- **Indicators of Compromise**: Users are encouraged to check for affected versions, specific filenames, and registry hashes related to the malicious releases.
- **Recovery Steps**: Immediate isolation of affected systems, rotation of sensitive credentials, and ensuring that installations use a known clean version are critical actions recommended for affected users.