Malicious code in abina-amibn-aguhai (npm)
The npm package abina-amibn-aguhai contains malicious autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. This package is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential installation by developers unaware of malicious intent
- Ecosystems
- Attack vectors
- Affected entities
- abina-amibn-aguhainpm package containing autopublish scripts
The npm package abina-amibn-aguhai was identified as containing malicious code as part of a coordinated campaign linked to the tea.xyz token reward program. The package includes autopublish scripts (such as auto.js, autopublish.js, and variants) that automatically execute upon installation.
The malicious payload modifies package.json files to remove private flags and alter version numbers, then generates derivative packages with randomized names—many using Indonesian-themed naming conventions—and continuously republishes them to the npm registry. This behavior is designed to artificially inflate developer reputation scores and pollute the registry with numerous variants.
The attack was identified through analysis by Amazon Inspector and credited to the OpenSSF's malicious-packages repository. The package represents part of a larger wave of similar malicious packages that exploited the tea protocol's token reward mechanism to incentivize registry pollution.
Indicators of compromise
- Packages
- abina-amibn-aguhai
Remediation
- Remove abina-amibn-aguhai and any derivative packages from your project dependencies immediately
- Audit package.json and lock files for any unexpected package additions or version changes
- Review npm account activity and authentication logs for unauthorized package publishes
- Clear npm cache and reinstall dependencies from a clean state
- Monitor for similar packages with randomized or Indonesian-themed names that may be variants of this campaign
Sources
- GitHub Advisory GHSA-r233-hp4q-2mjc · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amibn-aguhai (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amibn-aguhai-npm-82q2xi
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in rust-testing-utils (npm)
The npm package rust-testing-utils contained malicious code that impersonates the pino logger and executes remotely-fetched code with arbitrary privileges. The package spawns a child process that decodes a hardcoded URL, fetches attacker-controlled content, and executes it via Function constructor with full module-loading capability.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @syncraft-labs/core (npm)
The npm package @syncraft-labs/core contained obfuscated malicious code in its ESM build that executes on import, fetching and executing attacker-controlled payloads from Ethereum blockchain via JSON-RPC endpoints. The CommonJS build was clean, indicating targeted injection into the ESM entry point.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in dxr-dos (npm)
The npm package dxr-dos contains malicious code that executes arbitrary code via a mutable third-party dependency (deathoffather-project) and extracts a hidden PHP C2 panel from a password-protected archive. The package is advertised as a DDoS toolkit with command-and-control capabilities.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in ranux-pro (npm)
The npm package ranux-pro contained malicious code disguised as a network socket library. The package shipped a multi-tenant WhatsApp bot with obfuscated code and a mutable dependency override pointing to a personal GitHub account, allowing attackers to execute arbitrary code at install and runtime.
npmCompromised packageMalicious commit