Malicious code in abina-amoavugi-aninahi (npm)
The npm package abina-amoavugi-aninahi contains malicious code designed to automatically generate and publish derivative packages with randomized names to the npm registry. The package is part of a tea.xyz token reward campaign that exploited npm to inflate developer reputation scores.
- Disclosed
- Last updated
- Blast radius
- npm registry; developers who installed this package
- Ecosystems
- Attack vectors
- Affected entities
- abina-amoavugi-aninahimalicious npm package
The npm package abina-amoavugi-aninahi was identified as containing malicious code by Amazon Inspector and credited to OpenSSF's malicious-packages repository. The package appears to be part of a coordinated tea.xyz token reward campaign that flooded the npm registry with similar malicious packages.\n\nThe malicious payload includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and publish derivative packages with randomized names, primarily using Indonesian-themed naming conventions. The scripts modify package.json to remove private flags, alter version numbers, and continuously republish variants to pollute the npm registry.\n\nThe attack was designed to artificially inflate developer reputation scores within the tea protocol ecosystem by creating numerous derivative packages. This represents a supply chain attack that compromises the integrity of the npm registry and could affect any developer who installed this package or its generated derivatives.
Indicators of compromise
- Packages
- abina-amoavugi-aninahi
Remediation
- Remove the abina-amoavugi-aninahi package and all its derivatives from your project dependencies immediately
- Audit your npm registry and project dependencies for other packages from the tea.xyz token reward campaign
- Review your package.json and lock files for any unexpected package additions or version changes
- Check npm account activity for unauthorized package publications
- Monitor your systems for any unexpected network activity or package generation processes that may have been triggered by the malicious code
Sources
- GitHub Advisory GHSA-f7f6-rqwr-9xr6 · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amoavugi-aninahi (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amoavugi-aninahi-npm-10b6vo
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in gator-client
The npm package gator-client contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in @ai-vertical/ai-agent
Malware was discovered in the npm package @ai-vertical/ai-agent. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - containedcritical
Malware in junofficial-userbot
The npm package junofficial-userbot contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.
npmCompromised package - activecritical
Malware in cloud-agen-bot
The npm package cloud-agen-bot contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package