Malicious code in abina-amoavugi-anianahi (npm)
The npm package abina-amoavugi-anianahi contains malicious code designed to automatically generate and publish derivative packages with randomized names to the npm registry. The package is part of a broader campaign to inflate developer reputation scores for tea protocol token rewards by polluting the registry with auto-generated variants.
- Disclosed
- Last updated
- Blast radius
- npm registry; developers who installed this package and any derivative packages it auto-published
- Ecosystems
- Attack vectors
- Affected entities
- abina-amoavugi-anianahinpm package containing malicious autopublish scripts
The npm package abina-amoavugi-anianahi was identified as containing malicious code by Amazon Inspector and credited to OpenSSF's malicious-packages repository. The package includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically execute upon installation.
The malicious payload modifies package.json to remove private flags and alter version numbers, then generates random package names (primarily Indonesian-themed variants, with some English variants) and continuously republishes them to the npm registry. This behavior is designed to artificially inflate developer reputation metrics within the tea protocol ecosystem in exchange for token rewards.
The package is part of a larger coordinated campaign that flooded npm with similar malicious packages following the same pattern. The attack vector involves compromised or intentionally malicious package publication to the public npm registry, enabling widespread distribution to any developer who installs the package.
Remediation includes immediate removal of the package from affected systems, auditing npm dependencies for similar patterns, and monitoring for any derivative packages that may have been auto-published as a result of installation.
Indicators of compromise
- Packages
- abina-amoavugi-anianahi
Remediation
- Immediately uninstall abina-amoavugi-anianahi and any derivative packages from affected systems
- Audit npm dependencies for similar autopublish patterns and Indonesian/English-themed randomized package names
- Review npm account activity and publishing history for unauthorized package publications
- Monitor npm registry for any packages auto-published by this malicious code
- Consider using npm audit and supply chain security tools to detect similar malicious packages
- Report the package and any derivative packages to npm security team
Sources
- GitHub Advisory GHSA-mcfq-r6pm-mgwx · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amoavugi-anianahi (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amoavugi-anianahi-npm-14xlt5
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in rust-testing-utils (npm)
The npm package rust-testing-utils contained malicious code that impersonates the pino logger and executes remotely-fetched code with arbitrary privileges. The package spawns a child process that decodes a hardcoded URL, fetches attacker-controlled content, and executes it via Function constructor with full module-loading capability.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @syncraft-labs/core (npm)
The npm package @syncraft-labs/core contained obfuscated malicious code in its ESM build that executes on import, fetching and executing attacker-controlled payloads from Ethereum blockchain via JSON-RPC endpoints. The CommonJS build was clean, indicating targeted injection into the ESM entry point.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in dxr-dos (npm)
The npm package dxr-dos contains malicious code that executes arbitrary code via a mutable third-party dependency (deathoffather-project) and extracts a hidden PHP C2 panel from a password-protected archive. The package is advertised as a DDoS toolkit with command-and-control capabilities.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in ranux-pro (npm)
The npm package ranux-pro contained malicious code disguised as a network socket library. The package shipped a multi-tenant WhatsApp bot with obfuscated code and a mutable dependency override pointing to a personal GitHub account, allowing attackers to execute arbitrary code at install and runtime.
npmCompromised packageMalicious commit