Real-time Open Source Software Supply Chain Security

Reported 31 Aug 2026 by otx · Severity: medium

On August 28, 2026, an attacker published 10 malicious versions of the npm package @7nohe/openapi-react-query-codegen by exploiting a flawed GitHub Actions workflow. The release pipeline contained an issue_comment trigger without author-association gates, allowing any GitHub user