Popular npm Package With 150K+ Weekly Downloads Hit by Credential-Stealing Supply-Chain Worm

A widely used npm package has become a credential-stealing delivery channel after attackers planted a self-spreading Shai-Hulud payload in its releases. The affected @7nohe/openapi-react-query-codegen package, which generates TanStack Query code, receives more than 150,000 weekly downloads. The malicious releases can run while a developer installs dependencies or when npm processes a specially crafted build configuration file. That […]

This article has been indexed from Cyber Security News

Read the original article: