Malicious npm Package With Valid Provenance Highlights Limits of Supply Chain Trust

In late August 2026, an attacker exploited a misconfigured GitHub Actions workflow to publish ten malicious versions of the npm package @7nohe/openapi-react-query-codegen, with the workflow generating valid provenance pointing to the legitimate repository. The vulnerability stemmed from a setting that allowed any GitHub user to trigger a publish via pull request comments, enabling unauthorized fork code to authenticate to npm through OIDC. Security researchers noted that every campaign in the tracked Shai-Hulud worm taxonomy was detected within five days of release, making a simple dependency cooldown — via npm's min-release-age setting — an effective low-effort defense. Docker's Security Dispatch Issue 6 also introduces the Security Immediate Plan (SIP), a five-control framework covering AI agents, dependencies, container builds, attestations, and release gates for rapid incident response. The EU Cyber Resilience Act's reporting obligations are set to take effect on September 11, 2026, adding regulatory urgency to software supply chain security practices.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in