Type
Campaign
Actors
Pub. date
August 28, 2026
Initial access
Supply chain vector
Impact
Supply chain attackData exfiltration
Observed techniques
Observed tools
Targeted technologies
Status
Finalized
Last edited
Sep 7, 2026 2:30 PM
On August 28, starting at approximately 2000 UTC eight malicious versions of the @7nohe/openapi-react-query-codegen package were published on npm and were available for approximately three hours. These malicious versions were trojanized with an updated version of the miasma malware. As with previous versions, it gathers a wide range of credentials, the encrypts them and exfiltrates them by posting them to github, using keywords themed around the Touhou video game series to name the repositories. It also attempts to automatically spread via multiple channels.