Decision RecordActivePublished without chair review
CRT-2026-025001 Sep 2026AFTERNOON EDITIONDaily Roundtable
Response to a credential-stealing npm package
Immediately inventory environments for the malicious package and determine whether it executed. If execution is confirmed, rotate potentially exposed developer and cloud credentials and invalidate affected sessions.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
WeakThe evidence recorded through 2026-09-01 describes a credential-stealing npm package and explicitly supports immediate inventory.
If @7nohe/openapi-react-query-codegen executed in a development or build environment, developer and cloud credentials accessible there may require rotation. Waiting for exact affected versions would delay the investigation even though package presence and execution can be checked now.
Who is affected
Under reviewDevelopers whose workstations or development environments contain @7nohe/openapi-react-query-codegen may have developer credentials exposed if it executed.
Continuous-integration and build-runner operators must determine whether the package ran where cloud credentials or active sessions were accessible. Cloud account owners must rotate potentially exposed credentials and invalidate affected sessions when execution is confirmed.
Because affected versions are absent, maintainers cannot yet limit this investigation to named releases.
What supports this
Partially supported- Public incident summary — support: its excerpt states, “Malicious npm package steals developer and cloud credentials.” 2. Evidence review of the recorded interaction and incident material — support: it identifies a credential-stealing npm package and explicitly recommends immediate inventory followed by credential rotation when malicious execution is confirmed. 3. Recorded npm retrieval — context only: its excerpt names @7nohe/openapi-react-query-codegen and reports search results, but supplies no affected versions, hashes, or substantive containment findings. 4. Quarantine review — insufficient evidence: repository and runner quarantine language was traced to a separate Composer campaign. 5. Release-blocking review — evidence gap: precise blocking cannot be implemented without affected npm versions or hashes.
How the Roundtable reached this
Under reviewThe decision scout proposed inventorying @7nohe/openapi-react-query-codegen, quarantining repositories and runners, blocking malicious releases, and rotating credentials after confirmed execution.
The evidence auditors supported immediate inventory and conditional credential rotation but found two limits: quarantine evidence came from a separate Composer campaign, and no affected npm versions or hashes were available for precise blocking. The boundary reviewer endorsed that narrower scope.
The linker found no prior Decision Record to update, and the arbiter selected a new record limited to inventory, investigation, and rotation after confirmed execution.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 7 candidate signals.
- Linker (AI panel role)Linker evaluated 7 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 15 evidence signals; 8 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 11 public/private findings.
- Arbiter (AI panel role)Arbiter produced 7 decision envelopes.
Key disagreement
Scout (AI panel role)
Package presence alone does not prove that install scripts executed or credentials were taken.
Arbiter outcome
Arbiter outcome: new decision record. The evidence supports immediate inventory and investigation, followed by credential rotation when malicious execution is confirmed. Unsupported quarantine and release-specific blocking claims are excluded.
Candidates considered
Considered 7 candidates · opened 1 · 6 not opened (6 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingFinding @7nohe/openapi-react-query-codegen does not establish that its install code executed or that credentials were taken.
The affected release versions and hashes are unknown, so package presence cannot yet be narrowed by version. The available npm evidence also does not establish that repositories or runners require quarantine.
What evidence is missing
MissingThe evidence does not provide an authoritative list of affected @7nohe/openapi-react-query-codegen versions or package hashes.
It also lacks npm-specific evidence supporting repository or runner quarantine. Each deployment still needs lockfiles, package-manager logs, build artifacts, runner telemetry, and outbound-activity records to determine whether the package executed and whether credential rotation is triggered.
What would change this
Under reviewAn authoritative list of affected @7nohe/openapi-react-query-codegen versions or hashes would add precise release-blocking instructions.
npm-specific evidence that repositories or runners were compromised would justify quarantine or isolation.
Deployment evidence confirming execution triggers credential rotation and session invalidation; evidence showing the package was present but did not execute leaves the response at inventory and investigation.
What to watch next
Under reviewWatch lockfiles and package-manager logs for @7nohe/openapi-react-query-codegen, then correlate any match with build artifacts, runner telemetry, install-script execution, and outbound activity.
Treat confirmed execution as the trigger to rotate potentially exposed developer and cloud credentials and invalidate affected sessions. Watch for an authoritative advisory that supplies affected versions or hashes; use that publication as the trigger for precise dependency blocking.
Evidence basis
Public value history
- 01 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 01 Sep 2026Methodology
How the panel reaches a Public Decision Record.