@7nohe/openapi-react-query-codegen was compromised with 10 malicious releases.

The attacker abused a GitHub Actions issue_comment workflow to publish attacker-controlled code through the legitimate package pipeline.

Even more concerning: the malicious releases had valid npm provenance.

The payload can steal GitHub, npm, cloud and CI/CD credentials, modify GitHub Actions workflows, poison packages and establish persistence.

Known-good: 0.5.3, 1.6.2, 2.2.0, 3.0.2