npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Worm — Threadlinqs Intelligence
As of 2026-08-28, npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Worm is a critical-severity supply chain threat attributed to TeamPCP (suspected, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-2193 · Severity: CRITICAL · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: TeamPCP (suspected · FINANCIAL
All ten maintained release lines of @7nohe/openapi-react-query-codegen (~150,000 weekly downloads) were published with a 5.6MB obfuscated JavaScript loader after attackers abused a comment-triggered,
On 2026-08-28, Socket's Threat Research Team disclosed that @7nohe/openapi-react-query-codegen, a widely used React Query/TanStack Query code generator, had all ten of its maintained release lines (0.5.4-0.5.5, 1.6.3-1.6.4, 2.2.1-2.2.2, 3.0.3-3.0.4, plus two 0.0.0-<commit> prereleases) published in two waves roughly 20 minutes apart carrying a malicious payload. The attackers exploited a comment-triggered GitHub Actions publish workflow that gated only on the literal text "npm publish" without verifying the commenter's repository association, allowing an untrusted GitHub account to publish contents from a fork (github.com/p00paboot/openapi-react-query-codegen) under the legitimate repository's OIDC trusted-publishing identity. Because the resulting npm provenance attestations record the clean v3.0.2 commit on refs/heads/main, the malicious releases carry valid provenance and defeat `npm audit signatures` as a standalone control.
Execution is triggered without a conventional preinstall/postinstall script in most versions: an obfuscated `binding.gyp` uses Python object/class-hierarchy traversal to reach `os.system()` during node-gyp's native-build step, launching a single-byte-XOR-obfuscated ~5.7MB JavaScript file (`3FWCvzduYZg.js`). A later wave adds a direct `"preinstall": "node 3FWCvzduYZg.js"` trigger, and prerelease builds use alternate loaders (`is_it_this_simple.js`, `nu.js`) via a Bun-based installer path. At runtime the loader decrypts an embedded AES-128-GCM payload to a randomly named temp file, executes it with `child_process.execSync`, and deletes it immediately after.
The payload, which self-identifies in strings as "Trinitite: Sponsored by Preview 2 Effects," systematically harvests AWS (IMDSv2/instance-role/web-identity tokens), Azure (Microsoft Graph tenant/object/client data), GCP metadata/service-account tokens, and HashiCorp Vault secrets; validates and steals npm, PyPI, RubyGems, and JFrog Artifactory tokens; scrapes GitHub tokens and Actions secrets; and targets AI coding-agent configuration for Claude, GitHub Copilot, Cursor, Cline, and Aider. Discovery uses filesystem scanning of up to 12,000 files, `/proc/<pid>/mem` process-memory scraping on Linux, environment-variable enumeration, and cloud metadata probing. Confirmed secrets are used to poison other packages the victim can write to: npm/JFrog tarballs are modified and republished; owned RubyGems are downloaded, re-packed, and resubmitted; and PyPI typosquats are generated (up to 20 suffix variants such as `-mcp`/`-mpc`) and uploaded when the payload's `TYPO_MODE` flag is set. Where GitHub push access exists, the malware injects `.github/_index.js` and a deployment-triggered workflow named "ClaudeCode Review" that serializes repository secrets into an exfiltrated artifact, and separately propagates laterally over noninteractive SSH (`StrictHostKeyChecking=no`, `PasswordAuthentication=no`), SCP-ing `ai_setup.sh`/`ai_init.js` to reachable hosts and executing the implant remotely.
Host persistence is established via a macOS LaunchAgent (`~/Library/LaunchAgents/com.user.sysvinit-detect-fash.plist`, RunAtLoad/KeepAlive) or a Linux systemd user service with lingering enabled (`~/.config/systemd/user/sysvinit-detect-fash.service`), plus injected hook commands in VS Code/Cursor/Aider configuration that re-trigger the payload at session start. Collected data is chunked at 102,400 bytes, gzip-compressed, and encrypted with AES-256-GCM under an RSA-OAEP-wrapped key before being committed to newly created, randomly Touhou-themed public GitHub repositories for exfiltration. A separate command channel polls GitHub commit search hourly for the query `firedalazer`, parsing messages formatted `n1ggatr1n <base64-url>.<base64-signature>`, verifying them with RSA-PSS/SHA-256 against an embedded public key, and executing the resulting Python commands; a companion token-monitor polls the GitHub API once per minute for up to 259,200 seconds (72 hours) and `eval`s a stored
Weaknesses (CWE)
CWE-506, CWE-829, CWE-1357
Target sectors: technology, softwaredevelopment, saas, cloudinfrastructure
Target regions: Global
Timeline
- Microsoft publishes 'Shai-Hulud 2.0' guidance covering the broader self-propagating npm worm lineage that Socket later compares this incident's behavior against.
- Microsoft Security Blog reports 'Mini Shai-Hulud,' a resurgence compromising 170+ npm packages and 2 PyPI packages via CI/CD credential theft, establishing the campaign lineage Socket flags as behaviorally similar to this incident.
- Australian Federal Police, the FBI, and Western Australia Police arrest two alleged TeamPCP members (aged 21 and 23) in Cottesloe and Mandurah, WA; the 23-year-old is charged with six computer-related offences tied to prior supply-chain attacks.
- Security outlets (Help Net Security, BleepingComputer, The Hacker News, CyberScoop) report the TeamPCP arrests, describing over 1,000 organizations compromised, roughly 500,000 credentials stolen, and at least 300GB exfiltrated across TeamPCP's prior campaigns.
- Attackers exploit a comment-triggered, OIDC-backed npm publish GitHub Actions workflow on @7nohe/openapi-react-query-codegen that fails to verify commenter repository association, publishing 10 malicious version lines from a fork (github.com/p00paboot/openapi-react-query-codegen) in two waves roughly 20 minutes apart.
- The npm 'latest' dist-tag comes to point at compromised version 3.0.4; all ten malicious releases (0.5.4-0.5.5, 1.6.3-1.6.4, 2.2.1-2.2.2, 3.0.3-3.0.4, plus 2 prereleases) remain installable.
- Socket's Threat Research Team discovers and publicly discloses the compromise, publishing malware mechanics, credential-harvesting scope, persistence artifacts, and file-hash IOCs.
- Aikido Security publishes independent corroborating analysis identifying the malware's self-branding string 'Trinitite: Sponsored by Preview 2 Effects' and detailing the binding.gyp Python sandbox-escape execution vector, while flagging a possible but unconfirmed TeamPCP link despite the arrests two days earlier.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, T1195.001, T1195.002, T1059.007, T1059.006, T1059.004, T1543.001, T1543.002, T1027, T1140, T1070.004