Malicious code in abina-amiabuan-agu (npm)
The npm package abina-amiabuan-agu contains malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The payload modifies package.json, removes private flags, changes version numbers, and continuously republishes variants to pollute the npm registry.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential installation by developers unaware of malicious intent
- Ecosystems
- Attack vectors
- Affected entities
- abina-amiabuan-agunpm package containing malicious autopublish scripts
The npm package abina-amiabuan-agu was identified as containing malicious code as part of a broader tea.xyz token reward campaign that flooded the npm registry. The package includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) designed to automatically generate and publish derivative packages with randomized names, many with Indonesian-themed naming conventions.
The malicious payload modifies package.json to remove private flags, changes version numbers, and generates random package names for continuous republication. This activity is intended to inflate developer reputation scores within the tea protocol ecosystem to claim token rewards.
The attack represents a form of registry pollution and supply chain compromise, as the malicious packages could be installed by developers unaware of the malicious intent. The incident was identified and credited to the OpenSSF's malicious-packages repository.
Remediation involves removing the package from npm, auditing any systems that may have installed it, and reviewing npm logs for suspicious autopublish activity.
Indicators of compromise
- Packages
- abina-amiabuan-agu
Remediation
- Remove abina-amiabuan-agu and any derivative packages from npm
- Audit systems and CI/CD pipelines that may have installed this package
- Review npm audit logs for suspicious autopublish or package generation activity
- Check package.json files in projects for unexpected modifications or version changes
- Monitor for similar malicious packages as part of the tea.xyz campaign
Sources
- GitHub Advisory GHSA-54p8-96qh-6fjx · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amiabuan-agu (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amiabuan-agu-npm-1cu2on
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in core-tailwindcss-utility (npm)
core-tailwindcss-utility, an npm package falsely advertised as a Tailwind CSS utility, contains malicious code that fetches and executes arbitrary Node.js code from a remote C2 server. The package includes suspicious dependencies for credential theft and remote communication.
npmCompromised package - containedcritical
Malicious code in bcc-design-icons (npm)
bcc-design-icons@9999.0.0 on npm contains malicious postinstall script that exfiltrates hostname and package name to attacker-controlled IP 91.201.215.48:8000. The package lacks expected icon-library functionality and exhibits characteristics of a dependency-confusion attack targeting internal/private npm installers.
npmDependency confusionCompromised package - containedcritical
Malicious code in runtime-health (npm)
The npm package runtime-health version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malware in blastradar
Malware was discovered in the npm package blastradar, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package