Malicious code in @akunsansan0/susu9 (npm)
@akunsansan0/susu9 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential impact on developers who installed this package or its auto-generated derivatives.
- Ecosystems
- Attack vectors
- Affected entities
- @akunsansan0/susu9npm package containing malicious autopublish scripts
@akunsansan0/susu9 is a malicious npm package identified as part of a coordinated campaign to flood the npm registry with packages designed to game the tea.xyz token reward system. The package contains autopublish scripts (such as auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and publish derivative packages with randomized names, primarily using Indonesian-themed naming conventions alongside English variants.\n\nThe malicious payload modifies package.json to remove private flags and alter version numbers, enabling continuous republication of variants to the npm registry. This attack vector inflates developer reputation scores within the tea protocol ecosystem while simultaneously polluting the public npm registry with unwanted packages.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks such coordinated supply chain attacks. The package has been flagged with identifier MAL-2025-181344.
Indicators of compromise
- Packages
- @akunsansan0/susu9
Remediation
- Remove @akunsansan0/susu9 and any auto-generated derivative packages from your project dependencies
- Audit npm audit logs and package-lock.json for any installations of this package or related variants
- Review and update npm security policies to detect and block packages with autopublish or auto-generation scripts
- Monitor for similar patterns in the tea.xyz token reward campaign packages
- Report any discovered variants to the OpenSSF malicious-packages repository
Sources
- GitHub Advisory GHSA-gqx4-r9r4-w5w7 · GitHub Advisory Database
Cite this entry
"Malicious code in @akunsansan0/susu9 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu9-npm-19ex0m
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in kit-vim-map (npm)
The npm package kit-vim-map contained malicious code that executes a remote-controlled Linux ELF binary on installation, providing the attacker with arbitrary RCE, persistence, and file exfiltration capabilities. The binary beacons to C2 server 217.60.77.63 and establishes persistence via systemd user units.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in newtun (npm)
The newtun npm package contained malicious code that established a reverse shell connection to a hardcoded remote server (pull.7ii.win:7999), granting complete remote code execution and file system access to the attacker. The package exfiltrated system information and credentials while allowing arbitrary command execution and file manipulation.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in bjm-low-code-components (npm)
The npm package bjm-low-code-components contained malicious code in its postinstall hook that exfiltrated installer environment data (hostname, username, working directory, environment variables) to an attacker-controlled OAST endpoint. This reconnaissance beacon was designed to collect information about systems installing the package.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in sme-rko-finance-front-operations-income (npm)
The npm package sme-rko-finance-front-operations-income contained malicious code that downloads and executes platform-specific native binaries on package import. The package was disguised as a monitoring/observability SDK but contained no legitimate functionality.
npmCompromised packageMalicious commit