Malicious code in abina-amugmi-amamagu (npm)
The npm package abina-amugmi-amamagu contained malicious code designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modified package.json, removed private flags, and continuously polluted the npm registry with variants.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential impact on developers who installed the package or its auto-generated derivatives.
- Ecosystems
- Attack vectors
- Affected entities
- abina-amugmi-amamagunpm package containing malicious autopublish scripts
The npm package abina-amugmi-amamagu was identified as part of a coordinated campaign to flood the npm registry with malicious packages tied to the tea.xyz token reward program. The package contained autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) designed to automatically generate and republish derivative packages.
The malicious payload modified package.json to remove private flags and alter version numbers, then generated random package names (primarily Indonesian-themed variants, with some English variants) and continuously republished them to the registry. This behavior was intended to artificially inflate developer reputation scores for tea protocol token rewards.
The incident was identified and documented by the OpenSSF's malicious-packages repository, which tracks such threats to the npm ecosystem. The package represents a broader pattern of registry pollution attacks targeting token incentive programs.
Indicators of compromise
- Packages
- abina-amugmi-amamagu
Remediation
- Remove abina-amugmi-amamagu and any derivative packages from your dependencies immediately
- Audit your npm install history and project dependencies for any packages with randomized or suspicious names published around the same timeframe
- Review package.json and lock files for unexpected modifications or version changes
- Monitor your npm account for unauthorized package publications
- Report any suspicious packages to npm security team
Sources
- GitHub Advisory GHSA-mvm5-r5qv-hqgg · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amugmi-amamagu (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amugmi-amamagu-npm-w5gq61
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in sui-move-graphql
Malware was discovered in the npm package sui-move-graphql. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - resolvedcritical
Malicious code in bcc-design (npm)
bcc-design@9999.0.0 on npm is a dependency-confusion beacon package with no legitimate functionality. Its postinstall script exfiltrates the installer's hostname and system metadata to an attacker-controlled IP endpoint.
npmDependency confusionCompromised package - resolvedcritical
Malicious code in core-tailwindcss-utility (npm)
core-tailwindcss-utility, an npm package falsely advertised as a Tailwind CSS utility, contains malicious code that fetches and executes arbitrary Node.js code from a remote C2 server. The package includes suspicious dependencies for credential theft and remote communication.
npmCompromised package - containedcritical
Malware in blastradar
Malware was discovered in the npm package blastradar, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package