2026-10-11 16:38 UTC

StepSecurity researchers report @subql/[email protected] โ€” published through SubQuery's npm trusted-publisher (GitHub Actions OIDC) pipeline โ€” carries a postinstall credential stealer harvesting env vars, GitHub/SSH/cloud/Kubernetes/Vault secrets and AI-agent configs to ci-artifacts.dev, planting a secrets-dumping workflow branch and reverse shell; npm and maintainer remediation, victim scope, and the pipeline root-cause decide whether trusted publishing and install-time scripts remain a standing supply-chain exposure for developer and agent workflows.

state: watchingheat: mediumuncertainty: mediumknownscott: lowdeveloper-supply-chain agentic-security npm credential-theftSubQueryStepSecurity
Surfaced 2026-10-05T14:32:00Z โ€” "@subql/[email protected] (published 2026-10-05 11:56 UTC, currently the latest tag) contains a malicious payload that is not present in 5.8.2 .. โ€” StepSecurity researchers report @subql/[email protected] โ€” published through SubQuery's npm trusted-publisher (GitHub Actions OIDC) pipeline โ€” carries a postinstall credential stealer harvesting env vars, GitHub/SSH/cloud/Kubernetes/Vault secrets and AI-agent configs to ci-artifacts.dev, planting a secrets-dumping workflow branch and reverse shell; npm and maintainer remediation, victim scope, and the pipeline root-cause decide whether trusted publishing and install-time scripts remain a standing supply-chain exposure for developer and agent workflows.

What is this?

Per the case's own evidence, StepSecurity researchers report @subql/[email protected] โ€” the latest tag of SubQuery's npm package, published 2026-10-05 11:56 UTC through the project's GitHub Actions OIDC trusted-publisher pipeline โ€” carried a postinstall credential stealer exfiltrating env vars, GitHub/SSH/cloud/Kubernetes/Vault secrets and AI-agent configs to ci-artifacts.dev, plus a planted secrets-dumping workflow branch and reverse shell; the supplied web results do not corroborate this specific incident, so those details rest on the case's evidence titles alone. What the results do document is the campaign family it would join: StepSecurity and peers have reported repeated 2026 npm compromises abusing GitHub Actions OIDC trusted publishing โ€” the @bitwarden/cli hijack (described as the first confirmed abuse of npm's OIDC trusted publishing), the 'Miasma' backdooring of ~32 @redhat-cloud-services packages, and a ChainDrop worm spanning 444 packages / ~2,200 malicious versions โ€” each using install-time hooks to launch obfuscated stealers targeting the same secret classes plus AI tool configs, some with malicious-workflow injection and worm propagation. Note two gaps: whether SubQuery is a further instance of this family, and the claimed remediation/victim scope, are unconfirmed in the supplied material; and the documented family uses preinstall hooks while the case claims postinstall โ€” unverified either way.

Why it matters to Scott

Known ground: Scott's own wikis already carry this position โ€” ip:framework.siloos already treats the Shai-Hulud npm worm and install-script supply-chain policy as standing territory and designs exactly the containment (capability-scoped keys, no standing host secrets) whose absence this payload's credential inventory exploits, while ip:framework.breach-doesnt-compose already holds the non-transitive-compromise position one postinstall script re-illustrates. Per the grounding this repeats the already-documented 2026 OIDC trusted-publishing abuse family (Bitwarden CLI, Miasma, ChainDrop) with the same secret classes including AI-agent configs โ€” the world agreeing with him again, not news; it only upgrades if the pipeline root-cause turns out to bear on his own CI release workflows.
ip:framework.siloosip:framework.breach-doesnt-composeip:concept.sandboxed-executionradar:concept.software-supply-chainradar:concept.npm-supply-chainradar:concept.supply-chain-securityradar:concept.dependency-securityradar:shai-hulud-actions-reenabled
queries asked of Scott's wikis
  • npm trusted publishing OIDC release workflow
  • install scripts ignore-scripts supply chain policy
  • agent harness secrets env credential isolation
  • coding agent sandbox untrusted dependencies
  • Shai-Hulud npm worm campaign
  • AI agent config API keys MCP credential storage

Measured heat

now 0 pts/hpeak 15 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 171h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion

How the heat travelled

10-04 13:00โญ origin echo-reconstructed"@subql/[email protected] (published 2026-10-05 11:56 UTC, currently the latest tag) contains a malicious payload that is not present in 5.8.2 ..
sailikhith-stepsecurity on github (echo) ยท attributed from hn.story.49964244
โ€”
10-05 12:56first on hacker news ยท published ยท +23.9hSubql/common 5.8.3 compromised: postinstall stealer in 18k-star SubQuery repo
forxtrot
โ€”
10-05 12:56amplified on hacker news ๐Ÿ‘‘hn.story.49964244
forxtrot
peak 10 ยท 0 comments ยท 50% of case engagement
10-08 02:23amplified on hacker newshn.story.50001272
varunsharma07
peak 9 ยท 1 comments ยท 50% of case engagement
10-05 13:20our radar first saw it ยท +24.4hdiscovery anchor: hn.story.49964244โ€”
10-05 13:48reached heat=high ยท +24.8h ยท via ledgerโ€”โ€”
pace: p52 vs 1188 stories at the 168h mark (now 171h old) โ€” ahead of autobot-persistent-chatgpt-harness (1.1x), behind egma-voice-agent-simulation (0.9x)

Evidence (3) โ€” โญ canonical anchor

sourceobjectauthorscorecomments
๐ŸŸง hnSubql/common 5.8.3 compromised: postinstall stealer in 18k-star SubQuery repo
Retrieved article excerpt

Open article ยท Retrieved 2026-10-05T13:28:27.126247+00:00

[subquery](https://github.com/subquery) 
/
**[subql](https://github.com/subquery/subql)**
Public

- [Notifications](https://github.com/login?return_to=%2Fsubquery%2Fsubql) You must be signed in to change notification settings
- [Fork
  396](https://github.com/login?return_to=%2Fsubquery%2Fsubql)
- [Star
   18.7k](https://github.com/login?return_to=%2Fsubquery%2Fsubql)

# [security] : Malicious release @subql/[email protected] (postinstall credential stealer)ย #3047

New issue

Copy link

New issue

Copy link

Open

Open

[[security] : Malicious release @subql/[email protected] (postinstall credential stealer)](https://github.com/subquery/subql/issues/3047#top)#3047

Copy link

## Description

[@sailikhith-stepsecurity](https://github.com/sailikhith-stepsecurity)

[sailikhith-stepsecurity](https://github.com/sailikhith-stepsecurity)

opened [on Oct 5, 2026](https://github.com/subquery/subql/issues/3047#issue-5711801525)

Issue body actions

## Summary

`@subql/[email protected]` (published 2026-10-05 11:56 UTC, currently the `latest` tag) contains a malicious payload that is not present in 5.8.2. It was published through the project's npm trusted publisher (GitHub Actions OIDC) from gitHead [506863d6fb82bd2714970cf8c6f1bf364374b009](https://github.com/subquery/subql/commit/506863d6fb82bd2714970cf8c6f1bf364374b009). This suggests the release pipeline or a commit feeding it may be compromised.

**Please treat this as urgent: deprecate/unpublish 5.8.3, move `latest` back to 5.8.2, and rotate CI secrets.**

REF: <https://app.stepsecurity.io/oss-security-feed/@subql/common?version=5.8.3>

## What we found

Compared with 5.8.2, 5.8.3 adds:

- `package.json`: `"postinstall": "node ./dist/project/readers/manifest-cache.js"`
- New file `dist/project/readers/manifest-cache.js` (62,124 bytes)
- `dist/project/readers/index.js`: `__exportStar(require("./manifest-cache"), exports);`, so a plain `require('@subql/common')` also triggers it

The new file holds an array `MANIFEST_CACHE_SEED` of 459 base64 strings. They are decoded with a rolling XOR (start key `0x5a`) and gunzip, then run via `new Function(...)` in a detached process. The decoded 83 KB bundle:

- Collects environment variables, `gh auth token` output, SSH keys, `.npmrc`, cloud credentials (AWS/GCP/Azure), Kubernetes and Vault secrets, crypto wallets and AI-agent configs
- Sends the data encrypted (RSA-OAEP + AES-256-GCM) to `https://ci-artifacts.dev/router`
- Uses stolen GitHub tokens to push a branch `dependabot/github_actions/format/setup-formatter` containing `.github/workflows/codeql_analysis.yml`, which dumps `toJSON(secrets)` to an artifact. The commit author is spoofed as `github-advanced-security[bot]`.
- Installs a reverse-shell/command implant that beacons to the same host

## Indicators

- Domain: `ci-artifacts.dev`
- Tarball SHA-256: `031267ee37c5a84c25cb0542cbfeb49f30d5604305b0bdccdeafbedcbbe6849b`
- `manifest-cache.js` SHA-256: `f0c8b0cde86b98a2869a22fd43ffcf61f1dcca252729e2be291e590e3dc5f49a`
- Lock file: `$TMPDIR/tmp.ts018051808.lock`
- Branch name: `dependabot/github_actions/format/setup-formatter`

## Related version

`5.8.3-onf-rt1` (dist-tag `redteam`, published 2026-10-05 11:24 UTC, 32 minutes earlier) contains no payload. Please confirm whether it is an authorized test publish.

## Suggested actions

1. Deprecate/unpublish `@subql/[email protected]` and reset the `latest` tag to 5.8.2.
2. Review commit [506863d](https://github.com/subquery/subql/commit/506863d6fb82bd2714970cf8c6f1bf364374b009) and the release workflow run that published 5.8.3 for unauthorized changes.
3. Rotate the npm trusted-publisher configuration, GitHub tokens and all CI/Actions secrets for the repo and org.
4. Audit the repo and org for branches or workflows named as above and for unexpected runs.
5. Publish an advisory so users who installed 5.8.3 know to rotate credentials.

## Guidance for anyone who installed 5.8.3

Treat the machine or CI runner as compromised. Rotate GitHub, npm, cloud, Kubernetes and Vault credentials, and check your repos for the branch and workflow above.

Reactions are currently unavailable

## Activity

[Sign up for free](https://github.com/signup?return_to=https://github.com/subquery/subql/issues/3047) **to join this conversation on GitHub.** Already have an account? [Sign in to comment](https://github.com/login?return_to=https://github.com/subquery/subql/issues/3047)

## Metadata

## Metadata

### Assignees

No one assigned

### Labels

No labels

No labels

### Type

No type

### Projects

No projects

### Milestone

No milestone

### Relationships

None yet

### Development

No branches or pull requests

## Issue actions

- Open in GitHub Copilot app
forxtrot100
๐ŸŸง echo.github โญ"@subql/[email protected] (published 2026-10-05 11:56 UTC, currently the latest tag) contains a malicious payload that is not present in 5.8.2 ..sailikhith-stepsecurityโ€”โ€”
๐ŸŸง hnTensorlake NPM package and repo compromisedvarunsharma0791

Interpretation history

Decision trace