← Terug naar overzicht

Ten malicious versions of the npm package @7nohe/openapi-react-query-codegen were published by attackers who exploited an exposed npm publishing workflow in the package's CI/CD pipeline. The compromise allowed unauthorized publication of malicious package versions to the npm registry. The article details indicators of compromise (IOCs) associated with the malicious versions and provides recovery steps for affected users and maintainers. This incident highlights the risk of exposed secrets or misconfigured publishing workflows in open source projects. The attack falls under the category of software supply chain compromise, where downstream consumers of the package may have been impacted by installing the malicious versions.

Affected products

  • '@7nohe/openapi-react-query-codegen
  • npm

Categories

  • Supply Chain & Dependencies
  • Web Technologies