Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Malicious code in @cap-js/openapi (npm)

The npm package @cap-js/openapi was compromised and found to contain malicious code. The package steals credentials and propagates them to other packages it has access to, with persistence mechanisms. This is attributed to the "Mini Shai-Hulud is back" worm campaign by the TeamPCP threat actor.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All npm projects that depend on @cap-js/openapi
Ecosystems
Attack vectors
Affected entities
  • @cap-js/openapinpm package

The npm package @cap-js/openapi was identified as containing malicious code by multiple security sources including Amazon Inspector and Google Open Source Security. The compromise is attributed to the ongoing "Mini Shai-Hulud is back" worm campaign operated by the TeamPCP threat actor.

The malicious code in the package is designed to steal credentials from affected systems. Once credentials are obtained, the malware propagates them to every package the compromised environment has access to, enabling lateral movement and further compromise of the supply chain.

The malware also implements persistence mechanisms to maintain access across system restarts and package updates. This represents a significant supply chain risk to any project that has installed or depends on affected versions of @cap-js/openapi.

The incident was documented by the OpenSSF malicious packages repository (MAL-2026-4161) and confirmed by multiple independent security vendors.

Indicators of compromise

Packages
  • @cap-js/openapi

Remediation

  • Immediately audit all systems that have installed @cap-js/openapi for signs of compromise
  • Rotate all credentials and secrets that may have been exposed on affected systems
  • Remove @cap-js/openapi from all projects and replace with a clean, verified alternative
  • Review npm package.lock and yarn.lock files to identify all affected installations
  • Monitor for suspicious activity in dependent packages and repositories
  • Check for persistence mechanisms and remove any unauthorized access
  • Update to a patched version once available from the maintainers, or migrate to an alternative package

Sources

  1. GitHub Advisory GHSA-qj5h-p6mj-66pf · GitHub Advisory Database

Cite this entry

"Malicious code in @cap-js/openapi (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 27, 2026. https://supplychainattack.org/incident/malicious-code-in-cap-js-openapi-npm-8mg64m

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedhigh

    Microsoft links Mastra AI supply chain attack to North Korean hackers

    Microsoft attributed a Mastra AI supply chain attack that compromised over 140 npm packages to North Korean hacking group Sapphire Sleet (BlueNoroff). The attack targeted the npm ecosystem and AI development infrastructure.

    UNC1069npmAI agents & skillsCompromised packageMalicious maintainer
  2. activecritical

    Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat

    On June 17, 2026, an attacker compromised the @mastra npm organization and injected easy-day-js, a typosquat of the popular dayjs library, as a dependency across 140+ packages. The malicious package contained an obfuscated postinstall dropper that downloaded and executed a second-stage payload from attacker-controlled servers before self-deleting. The affected packages had a combined weekly download count exceeding 1.1 million.

    npmCompromised packageTyposquattingMalicious maintainer
  3. containedcritical

    Malicious code in polymarket-trader (npm)

    A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with evasion techniques targeting CI/CD scanners.

    npmMalicious maintainerCompromised package
  4. containedcritical

    Malicious code in polymarket-auto-trade (npm)

    A coordinated supply-chain attack published 9 malicious npm packages under the polymarketdev maintainer on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners.

    npmCompromised packageMalicious maintainer