Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

Popular code generator for TanStack Query hit by supply chain worm

A supply-chain worm embedded in the popular TanStack Query code generator @7nohe/openapi-react-query-codegen steals maintainer credentials and self-propagates to every package the victim publishes — an escalation beyond typical single-package compromises.

Summary written by editorial AI · Source link below

Filed by Aikido1 min readRead at source ↗

A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains. Category: Vulnerabilities & Threats

Editorial Analysis

Why it matters

Self-propagating npm supply-chain attacks can cascade across an organisation's entire internal and public package portfolio within hours.

What to do

Immediately audit for use of @7nohe/openapi-react-query-codegen, rotate exposed npm tokens, and enforce package provenance verification in CI pipelines.

Board brief

A worm-like npm supply-chain compromise can spread across all packages a developer maintains, creating cascading risk for any organisation consuming affected libraries.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Aikido

External link — opens at Aikido in a new tab.

§
Continue with

More from the Vulnerabilities Desk