Malicious code in abih-poke4 (npm)
The npm package abih-poke4 contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. This package was part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.
- Disclosed
- Last updated
- Blast radius
- Registry-wide pollution; affects developers who install abih-poke4 and any generated derivative packages
- Ecosystems
- Attack vectors
- Affected entities
- abih-poke4npm package containing malicious autopublish scripts
The npm package abih-poke4 was identified as containing malicious code as part of the tea.xyz token reward campaign. The package includes autopublish scripts (such as auto.js, autopublish.js, and variants) that automatically generate and publish derivative packages with randomized names to the npm registry.\n\nThe malicious payload modifies package.json files to remove private flags and alter version numbers, then generates random package names (primarily Indonesian-themed, with some English variants) and continuously republishes them. This activity was designed to artificially inflate developer reputation scores within the tea protocol ecosystem in exchange for token rewards.\n\nThe malicious behavior results in registry pollution, affecting the integrity of the npm ecosystem and potentially exposing developers who install the package or its generated derivatives to further supply chain risks.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- abih-poke4
Remediation
- Remove abih-poke4 and any derivative packages from your project dependencies immediately
- Audit your npm package.json and lock files for any packages with randomized or suspicious names that may have been auto-generated by this malicious package
- Clear your npm cache and reinstall dependencies from a clean state
- Review your npm account activity and publishing history for any unauthorized package publications
- Report any suspicious packages discovered to npm security team
- Monitor your projects for similar autopublish scripts in other dependencies
Sources
- GitHub Advisory GHSA-w839-pg86-q24m · GitHub Advisory Database
Cite this entry
"Malicious code in abih-poke4 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abih-poke4-npm-1f3xf7
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in mutex-thread (npm)
The npm package mutex-thread contained injected malicious code that spawns obfuscated dropper payloads, exfiltrates host reconnaissance data to Slack and Telegram, and executes remotely-controlled commands fetched from an Ethereum smart contract on Sepolia testnet.
npmCompromised packageMalicious commit - containedcritical
Malicious code in commandor-cli (npm)
commandor-cli@1.0.0 on npm contains malicious postinstall script that downloads and executes a binary from an attacker-controlled GitHub repository. The script also beacons installation metadata to a command-and-control server and includes a PowerShell bridge to extend execution to Windows hosts on WSL systems.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in agora402-payment-utils (npm)
The npm package agora402-payment-utils contains malicious code that replaces caller-supplied recipient addresses with a hardcoded Ethereum wallet (0xA930Ca05ea5548aE8ea0817087833A96453BED08) in payment routing functions. Additionally, a postinstall script exfiltrates installer metadata to an external webhook without consent.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @mohamed_nowisar/token3-check (npm)
The npm package @mohamed_nowisar/token3-check contained malicious code in preinstall, install, and postinstall lifecycle hooks that exfiltrated system and CI environment information to a third-party webhook endpoint without user consent.
npmCompromised packageMalicious commit