Shai-Hulud – Trinitite: Sponsored by Preview 2 Effects

Shai Hulud Trinitite
Share

TeamPCP went to jail, but the spirit of Shai-Hulud lives on: @7nohe/openapi-react-query-codegen was compromised, 128k weekly downloads affected

Overview

Less than 24h of TeamPCP’s creators arrest in Australia, a new Shai-Hulud malware variant hits npm, specifically compromising @7nohe/openapi-react-query-codegen, a TanStack query generator package.

This malware is a variant of the Shai-Hulud malware, now containing the string “Trinitite: Sponsored by Preview 2 Effects”, it contains the same code and signatures as the original open sourced version of the malware, which is highly similar to the Red Hat compromise we’ve seen in June.

The malware is bundled yet with a few new public encryption keys, which makes attribution to a specific hacking group or a previous Shai-Hulud variant much harder.

Who is affected

Anyone who installed a new version of @7nohe/openapi-react-query-codegen during the exposure period – 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4, and during August 28-29 2026.

Impact

  • 1 affected package.
  • Total accumulated weekly downloads – 128,223
  • 9 public GitHub repositories containing the “Trinitite: Sponsored by Preview 2 Effects” string, all from the same user.
  1. Rotate your keys and add 2FA to your accounts
  2. Downgrade the affected packages to a safe version
  3. Treat the affected machine as fully compromised

Infection Analysis

We found 9 infected repositories in GitHub containing stolen credentials, you can follow the infection as it spread in this link.

image

The infection is similar to what we’ve seen in the other Shai-Hulud Mini variants, where the stolen information is sent encrypted to a new repository in GitHub – but with two small changes –

  1. The JSON filename changed from “results” to “doubletrinnys”
  2. “meow meow meow” – a cat reference in the commit message itself.
image

When searching for infected repositories in GitHub, we can see that the first commit containing the “Trinitite: Sponsored by Preview 2 Effects” string appeared on 28 Aug 2026 17:33:49 -0500, showing that the infection on this variant was active 12 hours ago.

image

Technical Analysis

image

Since Shai-Hulud and its variants were dissected many times, we’ll try to focus on the new things seen in this “Trinitite: Sponsored by Preview 2 Effects” variant.

IndicatorPrevious VersionsCurrent Version
GitHub Repository DescriptionHades – The End for the DamnedTrinitite: Sponsored by Preview 2 Effects
GitHub C2 Commit Messagefiredalazern1ggatr1n
STATE_FILE variable/var/tmp/.gh_update_state/var/tmp/.shit
Key revoke threat messageDontRevokeOrItGoesBoomIfYouRevokeThisTokenYourABadUser
GitHub commit messagesTheBeautifulSnadsOfTimeVisit69WykenAveForFreeiPod
GitHub Actions YAMLname: Run Copilotname: ClaudeCode Review
Unused Domainapi.anthropic.compoopy[.]com

The malware also features a new unused string – “StopRapingMyBotnetPlz”, probably aimed towards researchers and agencies – 

image


The malware was updated to use Bun 1.4.0

image

The malware’s 1st stage obfuscated code, bundled inside the hijacked packages now contains a more obfuscated code, which removed the use of eval() in favor of Function for their code execution logic, and the use of XOR instead of ROT for deobfuscation.

Previous version

image

New version

image

First stage obfuscated payload comparison:

IndicatorPrevious VersionsCurrent Version
Execution functioneval()Function
Obfuscation TechniqueROT13XOR
Encryption TechniqueAES GCMAES GCM
Bun Version1.3.131.4.0

The malware also contains logic to download a new C2 payload from the remote server, according to our research, this logic is yet to be weaponized in this variant.

Conclusion

About two days after the two men behind TeamPCP were arrested, we see that their malware is still spreading in the wild affecting developers around the world.

It seems that their plan for going open source had a Joker effect on the cyber community, many imposters try to imitate them, hijacking accounts, spreading npm worms – while still wearing the same cat mask.

While security teams and the npm registry are here to clean the mess, it is probable that new actors, (with potentially a better opsec) will try to take the throne themselves.

While it’s possible that security teams will be able to mitigate the Shai-Hulud attacks, it seems that we’re going to have a lot more cat-themed malware in the future.

Or as the threat actors themselves say: “meow meow meow”

image

Affected Packages

Package nameAffected versions
@7nohe/openapi-react-query-codegen0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4

IOCs

  • Trinitite: Sponsored by Preview 2 Effects
  • n1ggatr1n
  • /var/tmp/.shit
  • IfYouRevokeThisTokenYourABadUser
  • Visit69WykenAveForFreeiPod
  • name: ClaudeCode Review
  • poopy[.]com

Public Keys

—–BEGIN PUBLIC KEY—–

MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAppkh3UB+fGCgmeoHnJ3M

A5LZL3jE3fwm6RjKGaYasah8d4bxNP55NsoCbdQAwvuFD/vpf3tYXRjo1aCahHPk

/oGgXUkC8LLaa1WPJQzYJu7qvqN5G9DyjRkl5sQbFmCsFoUz0Ks/4oeg8LZn17+q

fP+fbtO8KlZN/caxImqnDZGC2eH5iji9gTRsO/QKXNIfPX7typZVLhEWh+GOGXcT

avK4T6pNMQ9E5w8Hbj1It2wiq6P31BnUARVIkzbm0UpYm/oVj5H6iWl3rw3nzbr5

nvPkX5HxrNz6TkdVFcbhmvRLkn4Y+0NZUKJE4GvthJTK5Bii9NU2welomYWsVN33

iQIDAQAB

—–END PUBLIC KEY—–

—–BEGIN PUBLIC KEY—–

MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAmz8iJRlv/UJhhotMM6LN

PavfdyOh4LfsN0jXqjl2kfXwB5R8Z07GCU/+q0LmaYidyrc9qLeahMEL0eiex7Rn

cr5iF7mXTLiPVkILVLu3bElU0mbGuac/XzUjPvfo6tbRN8VxN3MwKhWMd1dCMcQE

D7Ui5Dv0+BxgNXudyo8lLdurz7AY/M+4CV4Wrr5m1XFDZMMCfnr4oDnkcUPHbXCd

O+GackIH0OlqcPY7/kCBugOsGHSbVQ1lVbhYRPqwKfUvSIWUVsWZlHal8WnSDCtZ

8NXkW/ZbZWsi4iNoOJzcdB13Q9lWgsUdJ+8XEnz6KZmr/AgpF9dDyZAZ1qutFbOi

S6k+j2yVj0nQGaEFb4yymlRcvAhB9n/GZzQLulhBdSzUeG1qUkV9yXHQ6I+TiBC+

6AVb3RhtCcQqT4suGCljl1pX53lQqS1Pp/iR2VmHAe+CU95zs0Vlr/7nfl0wPoMs

3HinFXH5PDLrs88XAsm07ZNVty3VXTy2q9A1/38qUYoQlG3uzcDGWFYOV3Qyeni8

Qz36Y4Mr/B8OQ5IxzBNaYdtsJ2fixFWQJaqFhuDuBCGOMpR22t+CPGEcNzY2qzhY

hR0MA9+gDxLecHFgjrhwqIpYnozz4cTowAB7p13GJWPDfN1gnaopHj60ytNkGMkC

z994jYW8IH1N1s9ccloDPUkCAwEAAQ==

—–END PUBLIC KEY—–

—–BEGIN PUBLIC KEY—–

MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA0bhzyYhwDarn+zsYQHNT

LSXaFanhfy/07hTqCbQw4sso5SArlmUtmMJtjYWHRC4sSXY6HQNVnlm1IXwANLIA

/PsV5ywa4050oxqe+khLDdCNG734N6kFf/TUDGAHW0nKErsv+PDsz7c642MK/vx4

tfpAv7tNbrePkwiofQbPLXoNvTBjXY75j7Fr7eI5qhBNZOZiHWl0BMWTNZqw/tEC

dDCbLqJXFHtllRQrdDEMh2IKzIc1yKhr/NuvQON7ngW+KNNmc0G+lf2X3iNb2phu

AyE9Alem76Xn/8vuX57zkSeXhYQTF2ZCZ54hMLGeOHTS3OTH480xLQ2i20mTb8s8

eyd9GKIU5Ehz6JVDH9KgatxG/DmNME8M7D1t0ZKP7SzWLvXjCBdVIJKp8UeCnqGr

fvReSIyLkZygj7isayFk/pMQHT0LQaYfWyABfd4TDRqAi8F/LALb5/XgNY1005iA

KT92x+0YjFYBEPpJvD5zJW2JwHrZwQ1f4wLhLh1J5KZsNBDJPmraw9tvveR2Pe4i

BZJaqNFJPSeTk4UKqcRhRx2Xn4HgDWBP0W7g3sbrYXBAi2JQdKpPXkcEOwu0TmEv

zK8yXInH+Pwbq5p7wPSTExt9sWOaqFPxaNpiDfZJRGzPlMPMatCsJSQ/lyJQ99SO

K2DiroKEwwjbyJD44/M+TY0CAwEAAQ==

—–END PUBLIC KEY—–

Tags:

OX VibeSec

Security That Moves at the Speed AI Builds

See what your AI agents decide and whether it’s safe before it runs. Connect a repo in minutes.

Get Your Software Secured