← Back

Wire · market

Shai-Hulud Trinitite Worm Infects Popular TanStack Query npm Package to Steal Developer Secrets

Published

31 August 2026

Topic

market

Sectors

Developer Tools

Source

Read at gbhackers.com

Verified

Fusion42 · 31 August 2026 · Fusion42 review

A sophisticated supply-chain attack named Shai-Hulud Trinitite infected a popular npm package, @7nohe/openapi-react-query-codegen, to steal developers' credentials across multiple platforms including GitHub, npm, cloud services, and Kubernetes.

This Wire brief sits within Fusion42's coverage of Developer Tools.

◆ The Wire takeaway

Your developer toolchain just became a vector for credential theft with npm supply-chain attacks evolving to hijack trusted release workflows. Now is the moment to audit your CI/CD pipelines and isolate any exposure to infected packages before attackers widen their reach.

Coverage

1 source · 31 Aug 2026

Related on Wire

Topics

Developer Toolssupply-chainnpmdeveloper-securitycredential-theftgithub-actionsnodejs