Malicious code in abina-amugmi-amtanamu (npm)
The npm package abina-amugmi-amtanamu contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that exploited npm to inflate developer reputation scores.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential installation by developers unaware of malicious intent
- Ecosystems
- Attack vectors
- Affected entities
- abina-amugmi-amtanamuMalicious npm package
The npm package abina-amugmi-amtanamu was identified as containing malicious code by Amazon Inspector and credited to OpenSSF's malicious-packages repository. The package includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and publish derivative packages with randomized names, primarily using Indonesian-themed naming conventions.\n\nThe malicious payload modifies package.json to remove private flags and alter version numbers, enabling continuous republication of variants to pollute the npm registry. This activity is part of a larger coordinated campaign associated with the tea.xyz token reward protocol, which flooded npm with similar malicious packages designed to artificially inflate developer reputation scores for token rewards.\n\nThe attack vector relies on unsuspecting developers installing the package, after which the autopublish mechanism operates autonomously to generate registry pollution and potentially compromise the integrity of the npm ecosystem.
Indicators of compromise
- Packages
- abina-amugmi-amtanamu
Remediation
- Remove abina-amugmi-amtanamu and any derivative packages from your project dependencies immediately
- Audit your npm install history and project dependencies for other packages with randomized or suspicious names, particularly those published around the same timeframe
- Review your npm account activity and authentication logs for unauthorized package publications
- Use npm audit and security scanning tools to detect similar malicious packages in your supply chain
- Report any installations of this package to npm security and your organization's security team
Sources
- GitHub Advisory GHSA-22xf-hx5m-rhwv · GitHub Advisory Database
Cite this entry
"Malicious code in abina-amugmi-amtanamu (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amugmi-amtanamu-npm-1liwjk
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in sui-move-graphql
Malware was discovered in the npm package sui-move-graphql. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - resolvedcritical
Malicious code in bcc-design (npm)
bcc-design@9999.0.0 on npm is a dependency-confusion beacon package with no legitimate functionality. Its postinstall script exfiltrates the installer's hostname and system metadata to an attacker-controlled IP endpoint.
npmDependency confusionCompromised package - resolvedcritical
Malicious code in core-tailwindcss-utility (npm)
core-tailwindcss-utility, an npm package falsely advertised as a Tailwind CSS utility, contains malicious code that fetches and executes arbitrary Node.js code from a remote C2 server. The package includes suspicious dependencies for credential theft and remote communication.
npmCompromised package - containedcritical
Malware in blastradar
Malware was discovered in the npm package blastradar, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package