Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in abina-amoavugi-aninahi (npm)

The npm package abina-amoavugi-aninahi contains malicious code designed to automatically generate and publish derivative packages with randomized names to the npm registry. The package is part of a tea.xyz token reward campaign that exploited npm to inflate developer reputation scores.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
npm registry; developers who installed this package
Ecosystems
Attack vectors
Affected entities
  • abina-amoavugi-aninahimalicious npm package

The npm package abina-amoavugi-aninahi was identified as containing malicious code by Amazon Inspector and credited to OpenSSF's malicious-packages repository. The package appears to be part of a coordinated tea.xyz token reward campaign that flooded the npm registry with similar malicious packages.\n\nThe malicious payload includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and publish derivative packages with randomized names, primarily using Indonesian-themed naming conventions. The scripts modify package.json to remove private flags, alter version numbers, and continuously republish variants to pollute the npm registry.\n\nThe attack was designed to artificially inflate developer reputation scores within the tea protocol ecosystem by creating numerous derivative packages. This represents a supply chain attack that compromises the integrity of the npm registry and could affect any developer who installed this package or its generated derivatives.

Indicators of compromise

Packages
  • abina-amoavugi-aninahi

Remediation

  • Remove the abina-amoavugi-aninahi package and all its derivatives from your project dependencies immediately
  • Audit your npm registry and project dependencies for other packages from the tea.xyz token reward campaign
  • Review your package.json and lock files for any unexpected package additions or version changes
  • Check npm account activity for unauthorized package publications
  • Monitor your systems for any unexpected network activity or package generation processes that may have been triggered by the malicious code

Sources

  1. GitHub Advisory GHSA-f7f6-rqwr-9xr6 · GitHub Advisory Database

Cite this entry

"Malicious code in abina-amoavugi-aninahi (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amoavugi-aninahi-npm-10b6vo

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in gator-client

    The npm package gator-client contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2. activecritical

    Malware in @ai-vertical/ai-agent

    Malware was discovered in the npm package @ai-vertical/ai-agent. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  3. containedcritical

    Malware in junofficial-userbot

    The npm package junofficial-userbot contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.

    npmCompromised package
  4. activecritical

    Malware in cloud-agen-bot

    The npm package cloud-agen-bot contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package