Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @akunsansan0/pucukharum (npm)

@akunsansan0/pucukharum is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
npm registry; developers who installed this package and its auto-generated derivatives
Ecosystems
Attack vectors
Affected entities
  • @akunsansan0/pucukharumnpm package containing malicious autopublish scripts

@akunsansan0/pucukharum is a malicious npm package identified as part of a coordinated campaign to flood the npm registry with packages designed to inflate developer reputation scores for tea protocol token rewards.

The package contains autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically modify package.json to remove private flags, alter version numbers, and generate random Indonesian-themed (and some English-themed) package names. These scripts then continuously republish variants to pollute the npm registry.

The malicious behavior was identified by Amazon Inspector and credited to the OpenSSF's malicious-packages repository. This represents a systematic attempt to manipulate the npm ecosystem for financial gain through token rewards.

Developers who installed this package or any of its auto-generated derivatives should immediately remove them and audit their systems for unauthorized package publications.

Indicators of compromise

Packages
  • @akunsansan0/pucukharum

Remediation

  • Remove @akunsansan0/pucukharum and any derivative packages from your project dependencies
  • Audit npm account for unauthorized package publications or modifications
  • Review package.json and lock files for unexpected package additions
  • Check npm publish history and revoke any suspicious access tokens
  • Monitor npm registry for any packages auto-generated by this malicious code
  • Report any discovered derivative packages to npm security team

Sources

  1. GitHub Advisory GHSA-7jw3-j44c-3q43 · GitHub Advisory Database

Cite this entry

"Malicious code in @akunsansan0/pucukharum (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed January 1, 2025; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-pucukharum-npm-1yo89n

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/f-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g-web-components (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in @antv/dipper-hooks (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antstackio/shelbysam (npm)

    The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit