Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in abih-poke24 (npm)

The npm package abih-poke24 contains malicious code designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Registry-wide pollution; affects npm ecosystem integrity and developer reputation systems
Ecosystems
Attack vectors
Affected entities
  • abih-poke24npm package containing malicious autopublish scripts

The npm package abih-poke24 was identified as containing malicious code as part of a broader tea.xyz token reward campaign that flooded the npm registry. The package includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) designed to automatically generate and publish derivative packages with randomized names.

The malicious payload modifies package.json to remove private flags and changes version numbers. It generates random Indonesian-themed package names (with some English variants) and continuously republishes these variants to pollute the npm registry. The primary objective is to artificially inflate developer reputation scores for tea protocol token rewards.

This incident was identified through Amazon Inspector and credited to the OpenSSF's malicious-packages repository, which tracks such supply chain attacks. The attack represents a systematic attempt to compromise npm registry integrity through automated package generation and publication.

Indicators of compromise

Packages
  • abih-poke24

Remediation

  • Remove abih-poke24 and all derivative packages from npm installations
  • Audit npm package.json for any unexpected dependencies or versions
  • Review npm account activity for unauthorized package publications
  • Monitor for other packages from the same campaign using similar autopublish patterns
  • Report any suspicious packages to npm security team
  • Consider using npm audit and supply chain security tools to detect similar malicious patterns

Sources

  1. GitHub Advisory GHSA-qh7j-rq8c-r8pf · GitHub Advisory Database

Cite this entry

"Malicious code in abih-poke24 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abih-poke24-npm-15dwal

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in rust-testing-utils (npm)

    The npm package rust-testing-utils contained malicious code that impersonates the pino logger and executes remotely-fetched code with arbitrary privileges. The package spawns a child process that decodes a hardcoded URL, fetches attacker-controlled content, and executes it via Function constructor with full module-loading capability.

    npmCompromised packageMalicious commit
  2. resolvedcritical

    Malicious code in @syncraft-labs/core (npm)

    The npm package @syncraft-labs/core contained obfuscated malicious code in its ESM build that executes on import, fetching and executing attacker-controlled payloads from Ethereum blockchain via JSON-RPC endpoints. The CommonJS build was clean, indicating targeted injection into the ESM entry point.

    npmCompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in dxr-dos (npm)

    The npm package dxr-dos contains malicious code that executes arbitrary code via a mutable third-party dependency (deathoffather-project) and extracts a hidden PHP C2 panel from a password-protected archive. The package is advertised as a DDoS toolkit with command-and-control capabilities.

    npmCompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in ranux-pro (npm)

    The npm package ranux-pro contained malicious code disguised as a network socket library. The package shipped a multi-tenant WhatsApp bot with obfuscated code and a mutable dependency override pointing to a personal GitHub account, allowing attackers to execute arbitrary code at install and runtime.

    npmCompromised packageMalicious commit