Malicious code in abina-amogoi-anuhi (npm)
The npm package abina-amogoi-anuhi contains malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously republishes variants to pollute the npm registry.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential installation by developers unaware of malicious intent
- Ecosystems
- Attack vectors
- Affected entities
- abina-amogoi-anuhinpm package containing malicious autopublish scripts
The npm package abina-amogoi-anuhi was identified as containing malicious code as part of a broader tea.xyz token reward campaign that flooded the npm registry. The package includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) designed to automatically generate and publish derivative packages with randomized names, many with Indonesian-themed naming conventions.
The malicious payload modifies package.json to remove private flags and changes version numbers, enabling continuous republication of variants. This activity is intended to artificially inflate developer reputation scores for tea protocol token rewards while polluting the npm registry with numerous derivative packages.
The incident was identified through Amazon Inspector and credited to the OpenSSF's malicious-packages repository, which tracks such supply chain attacks. The package represents a systematic attempt to abuse npm's publishing infrastructure for token reward manipulation.
Indicators of compromise
- Packages
- abina-amogoi-anuhi
Remediation
- Remove abina-amogoi-anuhi and any derivative packages from npm environments immediately
- Audit npm package.json files for unexpected dependencies on this package or its variants
- Review npm account activity and publishing history for unauthorized package publications
- Implement npm registry scanning and malicious package detection tools
- Monitor for and remove any packages generated by the autopublish scripts associated with this campaign
Sources
- GitHub Advisory GHSA-qq57-fm3j-w8pg · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amogoi-anuhi (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amogoi-anuhi-npm-1cphg0
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in checkout-common-tokens
Malware was discovered in the npm package checkout-common-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in chai-foundry
Malware was discovered in the npm package chai-foundry, affecting any computer with the package installed or running. The compromise grants full system control to an outside entity and requires immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in celonix-otp-react
Malware discovered in the npm package celonix-otp-react. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in checkout-create-pos-order-am
Malware discovered in the npm package checkout-create-pos-order-am. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package