Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in abina-amugmi-amiatanamu (npm)

The npm package abina-amugmi-amiatanamu contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. This package is part of a broader campaign exploiting the tea.xyz token reward system to artificially inflate developer reputation scores.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
npm registry; developers who installed this package and its auto-generated derivatives
Ecosystems
Attack vectors
Affected entities
  • abina-amugmi-amiatanamunpm package containing malicious autopublish scripts

The npm package abina-amugmi-amiatanamu was identified as containing malicious code by Amazon Inspector and credited to OpenSSF's malicious-packages repository. The package includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and publish derivative packages with randomized names, primarily using Indonesian-themed naming conventions.

The malicious payload modifies package.json to remove private flags and alter version numbers, enabling continuous republication of variants to pollute the npm registry. This activity is part of a larger campaign associated with the tea.xyz token reward system, which has flooded npm with similar malicious packages designed to artificially inflate developer reputation scores for token rewards.

Developers who installed this package or any of its auto-generated derivatives may have had their npm accounts or local environments compromised. The attack leverages npm's publishing mechanisms to distribute multiple variants and evade detection through name randomization.

Indicators of compromise

Packages
  • abina-amugmi-amiatanamu

Remediation

  • Immediately uninstall abina-amugmi-amiatanamu and any derivative packages with randomized or suspicious names from your project
  • Audit your npm account for unauthorized package publications and revoke any suspicious access tokens
  • Review your package.json and lock files for unexpected changes or new dependencies
  • Check your npm publish history for unauthorized package releases
  • Consider rotating npm authentication credentials if you suspect account compromise
  • Report any suspicious packages to npm security team at security@npmjs.com

Sources

  1. GitHub Advisory GHSA-7h3r-vcph-vqwh · GitHub Advisory Database

Cite this entry

"Malicious code in abina-amugmi-amiatanamu (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amugmi-amiatanamu-npm-d0vony

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in rust-testing-utils (npm)

    The npm package rust-testing-utils contained malicious code that impersonates the pino logger and executes remotely-fetched code with arbitrary privileges. The package spawns a child process that decodes a hardcoded URL, fetches attacker-controlled content, and executes it via Function constructor with full module-loading capability.

    npmCompromised packageMalicious commit
  2. resolvedcritical

    Malicious code in @syncraft-labs/core (npm)

    The npm package @syncraft-labs/core contained obfuscated malicious code in its ESM build that executes on import, fetching and executing attacker-controlled payloads from Ethereum blockchain via JSON-RPC endpoints. The CommonJS build was clean, indicating targeted injection into the ESM entry point.

    npmCompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in dxr-dos (npm)

    The npm package dxr-dos contains malicious code that executes arbitrary code via a mutable third-party dependency (deathoffather-project) and extracts a hidden PHP C2 panel from a password-protected archive. The package is advertised as a DDoS toolkit with command-and-control capabilities.

    npmCompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in ranux-pro (npm)

    The npm package ranux-pro contained malicious code disguised as a network socket library. The package shipped a multi-tenant WhatsApp bot with obfuscated code and a mutable dependency override pointing to a personal GitHub account, allowing attackers to execute arbitrary code at install and runtime.

    npmCompromised packageMalicious commit