Malicious code in abina-amibn-agu (npm)
The npm package abina-amibn-agu contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.
- Disclosed
- Last updated
- Blast radius
- npm registry; potential impact on developers who installed the package
- Ecosystems
- Attack vectors
- Affected entities
- abina-amibn-agunpm package containing malicious autopublish scripts
The npm package abina-amibn-agu was identified as containing malicious code as part of a broader tea.xyz token reward campaign that flooded the npm registry. The package included autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) designed to automatically generate and publish derivative packages with randomized names.
The malicious payload modified package.json to remove private flags and changed version numbers. It generated random Indonesian-themed package names (with some English variants) and continuously republished these variants to pollute the npm registry. The primary objective was to inflate developer reputation scores for tea protocol token rewards.
This incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks such threats to the npm ecosystem.
Indicators of compromise
- Packages
- abina-amibn-agu
Remediation
- Remove the abina-amibn-agu package from all projects and dependencies
- Audit npm package.json files for any unexpected derivative packages that may have been auto-published
- Review npm account activity for unauthorized package publications
- Update to a clean version of any legitimate packages that may have been affected
- Monitor npm registry for similar autopublish-based malicious packages
- Consider using npm audit and security scanning tools to detect similar threats
Sources
- GitHub Advisory GHSA-8vpg-h76x-g3ff · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amibn-agu (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amibn-agu-npm-1dzdyx
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in chlklib
Malware was discovered in the npm package chlklib, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in chai-as-deployer
Malware was discovered in the npm package chai-as-deployer, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malicious code in bcc-design-icons (npm)
bcc-design-icons@9999.0.0 on npm contains malicious postinstall script that exfiltrates hostname and package name to attacker-controlled IP 91.201.215.48:8000. The package lacks expected icon-library functionality and exhibits characteristics of a dependency-confusion attack targeting internal/private npm installers.
npmDependency confusionCompromised package - resolvedcritical
Malware in alphazone
The npm package alphazone contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.
npmCompromised package