A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates type-safe TanStack Query hooks. Aikido Security said it identified 10 malicious versions published within 20 minutes. Because the package records more than 150,000 weekly downloads, the incident poses exposure risk to development teams. The breach exposes developer workstations and CI systems […]
Read the original article: