Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)

A malicious npm package with an obfuscated name containing Spanish-language movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation count of the malicious package
Ecosystems
Attack vectors
Affected entities
  • -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-

An npm package named "-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-" was identified as containing malicious code. The package name appears designed to evade detection through obfuscation, using Spanish-language references to the movie "John Wick 4."

The malicious package was cataloged by the OpenSSF malicious packages project (reference MAL-2024-1678) and subsequently reported via GitHub Security Advisories. The incident was classified as critical severity.

The package has been identified and removed from circulation. Users who installed this package should remove it immediately and audit their systems for any unauthorized activity.

Indicators of compromise

Packages
  • -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-

Remediation

  • Remove the package from all environments where it was installed
  • Audit systems for any unauthorized code execution or data exfiltration
  • Review npm package installation logs to identify affected projects
  • Implement package name validation and typosquatting detection in dependency management workflows
  • Monitor for similar obfuscated package names in future npm registry scans

Sources

  1. GitHub Advisory GHSA-pjq6-hp79-gmrx · GitHub Advisory Database

Cite this entry

"Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 25, 2026; last updated July 25, 2026. https://supplychainattack.org/incident/malicious-code-in-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-va-qwlv7s

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  2. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  3. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  4. containedcritical

    Malicious code in -pem-misa (npm)

    The npm package -pem-misa contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised packageMalicious commit