Malicious code in @akunsansan0/susu10 (npm)
@akunsansan0/susu10 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential impact on developers who installed the package or its auto-generated derivatives.
- Ecosystems
- Attack vectors
- Affected entities
- @akunsansan0/susu10
@akunsansan0/susu10 is a malicious npm package identified as part of a coordinated campaign to flood the npm registry with packages designed to inflate developer reputation scores for tea protocol token rewards.\n\nThe package contains autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically modify package.json to remove private flags, alter version numbers, and generate random package names (primarily Indonesian-themed variants, with some English variants). These scripts then continuously republish the modified packages to the npm registry under new names.\n\nThis attack vector pollutes the npm registry with numerous derivative packages and could affect developers who installed the original package or any of its auto-generated variants. The incident was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.\n\nThe package has been flagged and removed from active distribution, though derivative packages may persist in the registry.
Indicators of compromise
- Packages
- @akunsansan0/susu10
Remediation
- Remove @akunsansan0/susu10 and any derivative packages from your project dependencies immediately
- Audit your npm audit logs and package-lock.json for any installations of this package or related auto-generated variants
- Review any packages with randomized or suspicious names that may have been auto-published as derivatives
- Update your npm client and enable security audits to detect similar malicious packages
- Report any discovered derivative packages to npm security team for removal
Sources
- GitHub Advisory GHSA-28hw-4x96-fghw · GitHub Advisory Database
Cite this entry
"Malicious code in @akunsansan0/susu10 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu10-npm-amksy3
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in @aligntech-cw/alignerfit (npm)
Malicious code was discovered in the npm package @aligntech-cw/alignerfit. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-1743.
npmCompromised package - containedcritical
Malicious code in @antv/f-wx (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/susu11 (npm)
@akunsansan0/susu11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously pollutes the npm registry with variants.
npmCompromised package - resolvedcritical
Malicious code in @akunsansan0/susu3 (npm)
@akunsansan0/susu3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
npmCompromised package