TeamPCP went to jail, but the spirit of Shai-Hulud lives on: @7nohe/openapi-react-query-codegen was compromised, 128k weekly downloads affected
Overview
Less than 24h of TeamPCP’s creators arrest in Australia, a new Shai-Hulud malware variant hits npm, specifically compromising @7nohe/openapi-react-query-codegen, a TanStack query generator package.
This malware is a variant of the Shai-Hulud malware, now containing the string “Trinitite: Sponsored by Preview 2 Effects”, it contains the same code and signatures as the original open sourced version of the malware, which is highly similar to the Red Hat compromise we’ve seen in June.
The malware is bundled yet with a few new public encryption keys, which makes attribution to a specific hacking group or a previous Shai-Hulud variant much harder.
Who is affected
Anyone who installed a new version of @7nohe/openapi-react-query-codegen during the exposure period – 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4, and during August 28-29 2026.
Impact
- 1 affected package.
- Total accumulated weekly downloads – 128,223
- 9 public GitHub repositories containing the “Trinitite: Sponsored by Preview 2 Effects” string, all from the same user.
Recommended Actions
- Rotate your keys and add 2FA to your accounts
- Downgrade the affected packages to a safe version
- Treat the affected machine as fully compromised
Infection Analysis
We found 9 infected repositories in GitHub containing stolen credentials, you can follow the infection as it spread in this link.

The infection is similar to what we’ve seen in the other Shai-Hulud Mini variants, where the stolen information is sent encrypted to a new repository in GitHub – but with two small changes –
- The JSON filename changed from “results” to “doubletrinnys”
- “meow meow meow” – a cat reference in the commit message itself.

When searching for infected repositories in GitHub, we can see that the first commit containing the “Trinitite: Sponsored by Preview 2 Effects” string appeared on 28 Aug 2026 17:33:49 -0500, showing that the infection on this variant was active 12 hours ago.

Technical Analysis

Since Shai-Hulud and its variants were dissected many times, we’ll try to focus on the new things seen in this “Trinitite: Sponsored by Preview 2 Effects” variant.
| Indicator | Previous Versions | Current Version |
| GitHub Repository Description | Hades – The End for the Damned | Trinitite: Sponsored by Preview 2 Effects |
| GitHub C2 Commit Message | firedalazer | n1ggatr1n |
| STATE_FILE variable | /var/tmp/.gh_update_state | /var/tmp/.shit |
| Key revoke threat message | DontRevokeOrItGoesBoom | IfYouRevokeThisTokenYourABadUser |
| GitHub commit messages | TheBeautifulSnadsOfTime | Visit69WykenAveForFreeiPod |
| GitHub Actions YAML | name: Run Copilot | name: ClaudeCode Review |
| Unused Domain | api.anthropic.com | poopy[.]com |
The malware also features a new unused string – “StopRapingMyBotnetPlz”, probably aimed towards researchers and agencies –

The malware was updated to use Bun 1.4.0

The malware’s 1st stage obfuscated code, bundled inside the hijacked packages now contains a more obfuscated code, which removed the use of eval() in favor of Function for their code execution logic, and the use of XOR instead of ROT for deobfuscation.
Previous version

New version

First stage obfuscated payload comparison:
| Indicator | Previous Versions | Current Version |
| Execution function | eval() | Function |
| Obfuscation Technique | ROT13 | XOR |
| Encryption Technique | AES GCM | AES GCM |
| Bun Version | 1.3.13 | 1.4.0 |
The malware also contains logic to download a new C2 payload from the remote server, according to our research, this logic is yet to be weaponized in this variant.
Conclusion
About two days after the two men behind TeamPCP were arrested, we see that their malware is still spreading in the wild affecting developers around the world.
It seems that their plan for going open source had a Joker effect on the cyber community, many imposters try to imitate them, hijacking accounts, spreading npm worms – while still wearing the same cat mask.
While security teams and the npm registry are here to clean the mess, it is probable that new actors, (with potentially a better opsec) will try to take the throne themselves.
While it’s possible that security teams will be able to mitigate the Shai-Hulud attacks, it seems that we’re going to have a lot more cat-themed malware in the future.
Or as the threat actors themselves say: “meow meow meow”

Affected Packages
| Package name | Affected versions |
| @7nohe/openapi-react-query-codegen | 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4 |
IOCs
- Trinitite: Sponsored by Preview 2 Effects
- n1ggatr1n
- /var/tmp/.shit
- IfYouRevokeThisTokenYourABadUser
- Visit69WykenAveForFreeiPod
- name: ClaudeCode Review
- poopy[.]com
Public Keys
—–BEGIN PUBLIC KEY—–
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAppkh3UB+fGCgmeoHnJ3M
A5LZL3jE3fwm6RjKGaYasah8d4bxNP55NsoCbdQAwvuFD/vpf3tYXRjo1aCahHPk
/oGgXUkC8LLaa1WPJQzYJu7qvqN5G9DyjRkl5sQbFmCsFoUz0Ks/4oeg8LZn17+q
fP+fbtO8KlZN/caxImqnDZGC2eH5iji9gTRsO/QKXNIfPX7typZVLhEWh+GOGXcT
avK4T6pNMQ9E5w8Hbj1It2wiq6P31BnUARVIkzbm0UpYm/oVj5H6iWl3rw3nzbr5
nvPkX5HxrNz6TkdVFcbhmvRLkn4Y+0NZUKJE4GvthJTK5Bii9NU2welomYWsVN33
iQIDAQAB
—–END PUBLIC KEY—–
—–BEGIN PUBLIC KEY—–
MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAmz8iJRlv/UJhhotMM6LN
PavfdyOh4LfsN0jXqjl2kfXwB5R8Z07GCU/+q0LmaYidyrc9qLeahMEL0eiex7Rn
cr5iF7mXTLiPVkILVLu3bElU0mbGuac/XzUjPvfo6tbRN8VxN3MwKhWMd1dCMcQE
D7Ui5Dv0+BxgNXudyo8lLdurz7AY/M+4CV4Wrr5m1XFDZMMCfnr4oDnkcUPHbXCd
O+GackIH0OlqcPY7/kCBugOsGHSbVQ1lVbhYRPqwKfUvSIWUVsWZlHal8WnSDCtZ
8NXkW/ZbZWsi4iNoOJzcdB13Q9lWgsUdJ+8XEnz6KZmr/AgpF9dDyZAZ1qutFbOi
S6k+j2yVj0nQGaEFb4yymlRcvAhB9n/GZzQLulhBdSzUeG1qUkV9yXHQ6I+TiBC+
6AVb3RhtCcQqT4suGCljl1pX53lQqS1Pp/iR2VmHAe+CU95zs0Vlr/7nfl0wPoMs
3HinFXH5PDLrs88XAsm07ZNVty3VXTy2q9A1/38qUYoQlG3uzcDGWFYOV3Qyeni8
Qz36Y4Mr/B8OQ5IxzBNaYdtsJ2fixFWQJaqFhuDuBCGOMpR22t+CPGEcNzY2qzhY
hR0MA9+gDxLecHFgjrhwqIpYnozz4cTowAB7p13GJWPDfN1gnaopHj60ytNkGMkC
z994jYW8IH1N1s9ccloDPUkCAwEAAQ==
—–END PUBLIC KEY—–
—–BEGIN PUBLIC KEY—–
MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA0bhzyYhwDarn+zsYQHNT
LSXaFanhfy/07hTqCbQw4sso5SArlmUtmMJtjYWHRC4sSXY6HQNVnlm1IXwANLIA
/PsV5ywa4050oxqe+khLDdCNG734N6kFf/TUDGAHW0nKErsv+PDsz7c642MK/vx4
tfpAv7tNbrePkwiofQbPLXoNvTBjXY75j7Fr7eI5qhBNZOZiHWl0BMWTNZqw/tEC
dDCbLqJXFHtllRQrdDEMh2IKzIc1yKhr/NuvQON7ngW+KNNmc0G+lf2X3iNb2phu
AyE9Alem76Xn/8vuX57zkSeXhYQTF2ZCZ54hMLGeOHTS3OTH480xLQ2i20mTb8s8
eyd9GKIU5Ehz6JVDH9KgatxG/DmNME8M7D1t0ZKP7SzWLvXjCBdVIJKp8UeCnqGr
fvReSIyLkZygj7isayFk/pMQHT0LQaYfWyABfd4TDRqAi8F/LALb5/XgNY1005iA
KT92x+0YjFYBEPpJvD5zJW2JwHrZwQ1f4wLhLh1J5KZsNBDJPmraw9tvveR2Pe4i
BZJaqNFJPSeTk4UKqcRhRx2Xn4HgDWBP0W7g3sbrYXBAi2JQdKpPXkcEOwu0TmEv
zK8yXInH+Pwbq5p7wPSTExt9sWOaqFPxaNpiDfZJRGzPlMPMatCsJSQ/lyJQ99SO
K2DiroKEwwjbyJD44/M+TY0CAwEAAQ==
—–END PUBLIC KEY—–