Malicious code in abih-poke22 (npm)
The npm package abih-poke22 contained malicious code designed to automatically generate and publish derivative packages with randomized names to the npm registry. The package was part of a broader campaign to inflate developer reputation scores for tea protocol token rewards.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential impact on developers who installed the package or its auto-generated derivatives
- Ecosystems
- Attack vectors
- Affected entities
- abih-poke22npm package containing malicious autopublish scripts
The npm package abih-poke22 was identified as containing malicious code by Amazon Inspector and credited to OpenSSF's malicious-packages repository. The package included autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generated and published derivative packages with randomized names, primarily using Indonesian-themed naming conventions alongside English variants.\n\nThe malicious payload modified package.json files to remove private flags and alter version numbers, enabling continuous republication of variants to pollute the npm registry. This activity was part of a larger campaign associated with the tea.xyz token reward initiative that resulted in numerous malicious packages being published to npm.\n\nThe attack vector involved compromised or intentionally malicious package publication rather than account takeover or build-system compromise. The primary goal was to artificially inflate developer reputation scores within the tea protocol ecosystem by generating high volumes of derivative packages.
Indicators of compromise
- Packages
- abih-poke22
Remediation
- Remove abih-poke22 and any derivative packages from npm installations
- Audit npm package.json files for unexpected or unfamiliar packages that may have been auto-generated and installed
- Review npm account activity and publishing history for unauthorized package publications
- Monitor for and remove any packages with randomized or suspicious names that may be derivatives of this malicious package
- Consider using npm audit and security scanning tools to detect similar malicious packages
Sources
- GitHub Advisory GHSA-2w78-7gff-hh7c · GitHub Advisory Database
Cite this entry
"Malicious code in abih-poke22 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abih-poke22-npm-dgdv9l
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in sui-move-graphql
Malware was discovered in the npm package sui-move-graphql. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - resolvedcritical
Malware in ulebkit
The npm package ulebkit contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malicious code in core-tailwindcss-utility (npm)
core-tailwindcss-utility, an npm package falsely advertised as a Tailwind CSS utility, contains malicious code that fetches and executes arbitrary Node.js code from a remote C2 server. The package includes suspicious dependencies for credential theft and remote communication.
npmCompromised package - containedcritical
Malware in blastradar
Malware was discovered in the npm package blastradar, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package