IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE13 IOCs

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

SS
Step Security
Published August 28, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYPlayINFRASTRUCTUREunknownCAPABILITYMETA StealerPlayVICTIMunknown
Adversary(1)
Infrastructure
Capability(2)
Victim

Indicators of Compromise

Indicators of Compromise13

TypeIndicatorConfidenceScoreFirst Seen
SHA1fc60551b23485829c0a6e910224b049c891a49b8
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA16499c9ab4e60f9b1db6756cb0de55ebc334a72d1
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1e7a07ca4a3cd51c262495f473abe4c4e505b7be4
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA12d934cf137a4e62519f88e7ab669d2fabda33867
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA256b24d121667f21f492cb9db34fbfd515d5922a8dd30b9c45215c7220abbb10ca8
file-hashindicatorintel-blog
Medium
36
Aug 30, 26
SHA1365d4eb738d3146583431948d3ba6e27a32556be
aptespionagefile-hash
Medium
53
Oct 9, 26
SHA13fc635b988db2bd647b8578dfc1a85769913b708
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1ec7876d6c917dad516ba69bbfafc948b834bf0ab
exploitfile-hashintel-blog
Medium
53
Oct 9, 26
SHA1337ae261e4e73a9f365f892dcef2dc6f6932e90a
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1206b18c418434abc994bd40e021edcc334eee89b
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1bafa4edaa6812fce10ae703ae450cc88ebbe1730
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA10f9bc76952b67d7a28a57d1e726293f417df0119
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA15ab130e4736d4582899af2385ec7eb5a33619d05
file-hashintel-blogmalware
Medium
53
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph13 total IOCs
SHA1SHA256
SHA112SHA2561Actors1Malware2REPORT@7nohe/openapi-react-queryPlayMETA StealerPlay
scroll to zoom · drag to pan · click IOC to open