Malicious code in abina-amugi-anupai (npm)
The npm package abina-amugi-anupai contains malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously republishes variants to pollute the npm registry.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential installation by developers unaware of malicious intent
- Ecosystems
- Attack vectors
- Affected entities
- abina-amugi-anupainpm package containing malicious autopublish scripts
The npm package abina-amugi-anupai was identified as containing malicious code as part of a broader campaign associated with the tea.xyz token reward initiative. The package includes autopublish scripts (such as auto.js, autopublish.js, autopublish2.js, and autopublish3.js) that are designed to automatically generate and publish derivative packages with randomized names.
The malicious payload modifies package.json to remove private flags and changes version numbers, then generates random Indonesian-themed package names (with some English variants) and continuously republishes these variants to pollute the npm registry. The intent is to artificially inflate developer reputation scores for tea protocol token rewards.
This package was identified by Amazon Inspector and credited to the OpenSSF's malicious-packages repository. The attack represents a form of registry pollution and supply chain compromise targeting the npm ecosystem.
Indicators of compromise
- Packages
- abina-amugi-anupai
Remediation
- Remove abina-amugi-anupai and any derivative packages from your project dependencies immediately
- Audit your npm package.json and lock files for any unexpected or unfamiliar packages, particularly those with randomized or unusual names
- Review your npm account activity and publishing history for unauthorized package publications
- Consider using npm audit and security scanning tools to detect similar malicious packages
- Monitor the OpenSSF malicious-packages repository for updates on related packages from this campaign
Sources
- GitHub Advisory GHSA-7hrh-xj7q-p48x · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amugi-anupai (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed January 1, 2025; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amugi-anupai-npm-12ff0f
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in agentsync-pkg
Malware discovered in the npm package agentsync-pkg. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in envfile-sync-cli
Malware was discovered in the npm package envfile-sync-cli, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @zizie071/libsignal-node
The npm package @zizie071/libsignal-node contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in @siwatfa/yorn
Malware was discovered in the npm package @siwatfa/yorn. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package