Malicious code in abina-amoavugoi-anuinahi (npm)
The npm package abina-amoavugoi-anuinahi contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. This package is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages intended to inflate developer reputation scores.
- Disclosed
- Last updated
- Blast radius
- npm registry; developers who installed this package or its derivative variants
- Ecosystems
- Attack vectors
- Affected entities
- abina-amoavugoi-anuinahinpm package containing malicious autopublish scripts
The npm package abina-amoavugoi-anuinahi was identified as containing malicious code by Amazon Inspector and credited to OpenSSF's malicious-packages repository. The package includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that execute automatically upon installation.
The malicious payload modifies package.json to remove private flags and alter version numbers, then generates random package names (primarily Indonesian-themed variants, with some English variants) and continuously republishes them to pollute the npm registry. This behavior is consistent with a coordinated campaign to artificially inflate developer reputation scores for tea protocol token rewards.
The package represents a supply chain attack vector targeting npm developers and the integrity of the registry itself. Any developer who installed this package or its derivative variants would have had their npm account and publishing credentials potentially compromised or misused.
Indicators of compromise
- Packages
- abina-amoavugoi-anuinahi
Remediation
- Immediately uninstall abina-amoavugoi-anuinahi and any derivative packages with randomized or suspicious names from all environments
- Audit npm account activity and publishing history for unauthorized package publications
- Review and rotate npm authentication tokens and credentials if this package was installed in a development or CI/CD environment
- Check project dependencies for any variants of this package or other packages from the tea.xyz campaign
- Report any unauthorized package publications to npm security team
- Monitor npm registry for additional malicious packages from this campaign
Sources
- GitHub Advisory GHSA-3vr8-72vv-g6hg · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amoavugoi-anuinahi (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amoavugoi-anuinahi-npm-1m8828
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in sui-move-graphql
Malware was discovered in the npm package sui-move-graphql. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - resolvedcritical
Malicious code in bcc-design (npm)
bcc-design@9999.0.0 on npm is a dependency-confusion beacon package with no legitimate functionality. Its postinstall script exfiltrates the installer's hostname and system metadata to an attacker-controlled IP endpoint.
npmDependency confusionCompromised package - resolvedcritical
Malicious code in core-tailwindcss-utility (npm)
core-tailwindcss-utility, an npm package falsely advertised as a Tailwind CSS utility, contains malicious code that fetches and executes arbitrary Node.js code from a remote C2 server. The package includes suspicious dependencies for credential theft and remote communication.
npmCompromised package - containedcritical
Malware in blastradar
Malware was discovered in the npm package blastradar, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package