Popular code generator for TanStack Query hit by supply chain worm
aikido.dev | incident | #supply-chain | #threat-intelligence | #malware | #github-actions | #npm | #javascript-security | #aikido | #binding-gyp | #tanstack
Summary
Aikido: ten versions of @7nohe/openapi-react-query-codegen (150k weekly downloads) were poisoned in 20 minutes; the worm exploits a GitHub Actions flaw and node-gyp's Python evaluation of binding.gyp.
Why it matters
This incident coverage highlights active npm package poisoning and practical supply chain defensive lessons.
- Published
- Collected
Skip to content