Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in abina-amugui-anumai (npm)

The npm package abina-amugui-anumai contains malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously republishes variants to pollute the npm registry.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Registry pollution; potential impact on developers who installed the package and any downstream dependencies
Ecosystems
Attack vectors
Affected entities
  • abina-amugui-anumainpm package containing malicious autopublish scripts

The npm package abina-amugui-anumai was identified as containing malicious code as part of a broader tea.xyz token reward campaign that flooded npm with similar packages. The malicious payload includes autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) designed to automatically generate and publish derivative packages with randomized names, many with Indonesian-themed naming conventions.

The malicious behavior modifies package.json to remove private flags, changes version numbers, and continuously republishes variants to pollute the npm registry. The primary objective is to inflate developer reputation scores for tea protocol token rewards by artificially increasing the number of published packages associated with the attacker's account.

This incident was identified by Amazon Inspector and credited to the OpenSSF's malicious-packages repository, which tracks known malicious packages across package ecosystems. The package has been flagged and removed from the npm registry.

Indicators of compromise

Packages
  • abina-amugui-anumai

Remediation

  • Remove abina-amugui-anumai from all projects and dependencies
  • Audit npm audit logs for any suspicious package installations or publishes
  • Review and revoke any npm tokens that may have been compromised
  • Check for any derivative packages with randomized or Indonesian-themed names that may have been published as a result of this malicious package
  • Monitor npm registry for similar packages as part of the tea.xyz campaign

Sources

  1. GitHub Advisory GHSA-v7gx-m58v-xq3m · GitHub Advisory Database

Cite this entry

"Malicious code in abina-amugui-anumai (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 14, 2026; last updated August 14, 2026. https://supplychainattack.org/incident/malicious-code-in-abina-amugui-anumai-npm-1ll5ry

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in rust-testing-utils (npm)

    The npm package rust-testing-utils contained malicious code that impersonates the pino logger and executes remotely-fetched code with arbitrary privileges. The package spawns a child process that decodes a hardcoded URL, fetches attacker-controlled content, and executes it via Function constructor with full module-loading capability.

    npmCompromised packageMalicious commit
  2. resolvedcritical

    Malicious code in @syncraft-labs/core (npm)

    The npm package @syncraft-labs/core contained obfuscated malicious code in its ESM build that executes on import, fetching and executing attacker-controlled payloads from Ethereum blockchain via JSON-RPC endpoints. The CommonJS build was clean, indicating targeted injection into the ESM entry point.

    npmCompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in dxr-dos (npm)

    The npm package dxr-dos contains malicious code that executes arbitrary code via a mutable third-party dependency (deathoffather-project) and extracts a hidden PHP C2 panel from a password-protected archive. The package is advertised as a DDoS toolkit with command-and-control capabilities.

    npmCompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in ranux-pro (npm)

    The npm package ranux-pro contained malicious code disguised as a network socket library. The package shipped a multi-tenant WhatsApp bot with obfuscated code and a mutable dependency override pointing to a personal GitHub account, allowing attackers to execute arbitrary code at install and runtime.

    npmCompromised packageMalicious commit