Malicious code in @akunsansan0/kopi3 (npm)
@akunsansan0/kopi3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
- Disclosed
- Last updated
- Blast radius
- npm registry; developers who installed @akunsansan0/kopi3
- Ecosystems
- Attack vectors
- Affected entities
- @akunsansan0/kopi3npm package containing malicious autopublish scripts
@akunsansan0/kopi3 is a malicious npm package identified as part of a coordinated campaign to flood the npm registry with packages designed to game the tea.xyz token reward system. The package contains autopublish scripts (such as auto.js, autopublish.js, autopublish2.js, autopublish3.js) that execute automatically upon installation.
The malicious payload modifies the package.json file to remove private flags and alter version numbers. It then generates derivative packages with randomized names—primarily Indonesian-themed but also English variants—and automatically publishes them to the npm registry. This behavior is designed to artificially inflate developer reputation scores and claim token rewards from the tea protocol.
The attack represents a form of registry pollution and reputation manipulation rather than traditional code execution attacks. However, the automated republishing of modified packages poses a significant threat to registry integrity and can mislead developers about package provenance and authenticity.
This incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks such coordinated malicious publishing campaigns.
Indicators of compromise
- Packages
- @akunsansan0/kopi3
Remediation
- Remove @akunsansan0/kopi3 and any derivative packages from your dependencies immediately
- Audit your npm install history and check for any packages with randomized or suspicious names that may have been auto-published variants
- Clear your node_modules directory and reinstall dependencies from a clean state
- Review package.json for any unexpected modifications or version changes
- Monitor your npm account for unauthorized package publications
- Report the package and any related variants to npm security team
Sources
- GitHub Advisory GHSA-w6f8-q979-582x · GitHub Advisory Database
Cite this entry
"Malicious code in @akunsansan0/kopi3 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-kopi3-npm-1n8owj
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in @aligntech-cw/alignerfit (npm)
Malicious code was discovered in the npm package @aligntech-cw/alignerfit. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-1743.
npmCompromised package - resolvedcritical
Malicious code in @akunsansan0/susu10 (npm)
@akunsansan0/susu10 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.
npmCompromised package - containedcritical
Malicious code in @antv/f-wx (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/susu11 (npm)
@akunsansan0/susu11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously pollutes the npm registry with variants.
npmCompromised package