Popular code generator for TanStack Query hit by supply chain worm
A supply-chain worm embedded in the popular TanStack Query code generator @7nohe/openapi-react-query-codegen steals maintainer credentials and self-propagates to every package the victim publishes — an escalation beyond typical single-package compromises.
Summary written by editorial AI · Source link below
A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains. Category: Vulnerabilities & Threats
Editorial Analysis
Self-propagating npm supply-chain attacks can cascade across an organisation's entire internal and public package portfolio within hours.
Immediately audit for use of @7nohe/openapi-react-query-codegen, rotate exposed npm tokens, and enforce package provenance verification in CI pipelines.
A worm-like npm supply-chain compromise can spread across all packages a developer maintains, creating cascading risk for any organisation consuming affected libraries.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
More from the Vulnerabilities Desk
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities3d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacks3d