
Popular npm Package With 150K Weekly Downloads Hit by Credential-Stealing Worm
The npm package @7nohe/openapi-react-query-codegen, which receives roughly 150,000 weekly downloads, has been compromised by a malicious campaign linked by researchers to the Mini Shai-Hulud activity. The Socket Threat Research Team found that attackers published 10 malicious versions of the package on August 28, 2026, across every maintained release line. The malicious versions remain installable, with […]
The post Popular npm Package With 150K Weekly Downloads Hit by Credential-Stealing Worm appeared first on Cyber Security News.