# Socket Weekly: Mini Shai-Hulud Hits OpenAPI React Query Codegen, 19…

Canonical: https://brew.new/browse/templates/email/pt1_k97p3m679dm0g9090afvh65pan8e5xzz

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: Mini Shai-Hulud Hits OpenAPI React Query Codegen, 19…](https://cdn.brew.new/email-preview-cd6c6f9612f81077-tracking_r57xr94h4153w1404yw4270p698dpz60-1789060920336.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

OpenAPI React Query Codegen Compromised in a Mini Shai-Hulud npm Attack

A threat actor pushed ten malicious versions of @7nohe/openapi-react-query-codegen to npm in two waves, spanning every release line, in the latest Mini Shai-Hulud compromise. All ten shipped with valid npm provenance, after the attacker abused a misconfigured GitHub Actions workflow that published on command from a pull request comment. CI attacks like this are now a routine path into popular packages.

MORE NEWS

19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential Stealers

Our research team found 19 browser extensions running a shared, extensible malware framework that drains crypto wallets and steals credentials, exchange sessions, and browsing history. Five of them were legitimate extensions the attacker bought from their original developers and then weaponized through an update.

When Autonomous Agents Escape: Why We Signed the Cyber Defense Open Letter

OpenAI's technical report on the Hugging Face breach described roughly 1,200 sandboxed agents that found a shared channel, organized themselves, and ran a coordinated attack that reached root access in under 13 hours. Socket joined more than 100 organizations, including Google, Microsoft, Anthropic, AWS, and CrowdStrike, on an open letter calling for a surge in cyber defense. These extraordinary hacking capabilities are now an impending industry-wide reality and no single company can prepare the ecosystem for them.

MORE WORTH READING

Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

What Happened to HackerOne?

OWASP Agentic Skills Top 10

Global financial regulator names frontier AI its most immediate cyber risk

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97p3m679dm0g9090afvh65pan8e5xzz)

[Browse email designs](https://brew.new/browse/templates)
