Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @akunsansan0/susu9 (npm)

@akunsansan0/susu9 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Registry pollution; potential impact on developers who installed this package or its auto-generated derivatives.
Ecosystems
Attack vectors
Affected entities
  • @akunsansan0/susu9npm package containing malicious autopublish scripts

@akunsansan0/susu9 is a malicious npm package identified as part of a coordinated campaign to flood the npm registry with packages designed to game the tea.xyz token reward system. The package contains autopublish scripts (such as auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and publish derivative packages with randomized names, primarily using Indonesian-themed naming conventions alongside English variants.\n\nThe malicious payload modifies package.json to remove private flags and alter version numbers, enabling continuous republication of variants to the npm registry. This attack vector inflates developer reputation scores within the tea protocol ecosystem while simultaneously polluting the public npm registry with unwanted packages.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks such coordinated supply chain attacks. The package has been flagged with identifier MAL-2025-181344.

Indicators of compromise

Packages
  • @akunsansan0/susu9

Remediation

  • Remove @akunsansan0/susu9 and any auto-generated derivative packages from your project dependencies
  • Audit npm audit logs and package-lock.json for any installations of this package or related variants
  • Review and update npm security policies to detect and block packages with autopublish or auto-generation scripts
  • Monitor for similar patterns in the tea.xyz token reward campaign packages
  • Report any discovered variants to the OpenSSF malicious-packages repository

Sources

  1. GitHub Advisory GHSA-gqx4-r9r4-w5w7 · GitHub Advisory Database

Cite this entry

"Malicious code in @akunsansan0/susu9 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu9-npm-19ex0m

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in kit-vim-map (npm)

    The npm package kit-vim-map contained malicious code that executes a remote-controlled Linux ELF binary on installation, providing the attacker with arbitrary RCE, persistence, and file exfiltration capabilities. The binary beacons to C2 server 217.60.77.63 and establishes persistence via systemd user units.

    npmCompromised packageMalicious commit
  2. resolvedcritical

    Malicious code in newtun (npm)

    The newtun npm package contained malicious code that established a reverse shell connection to a hardcoded remote server (pull.7ii.win:7999), granting complete remote code execution and file system access to the attacker. The package exfiltrated system information and credentials while allowing arbitrary command execution and file manipulation.

    npmCompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in bjm-low-code-components (npm)

    The npm package bjm-low-code-components contained malicious code in its postinstall hook that exfiltrated installer environment data (hostname, username, working directory, environment variables) to an attacker-controlled OAST endpoint. This reconnaissance beacon was designed to collect information about systems installing the package.

    npmCompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-income (npm)

    The npm package sme-rko-finance-front-operations-income contained malicious code that downloads and executes platform-specific native binaries on package import. The package was disguised as a monitoring/observability SDK but contained no legitimate functionality.

    npmCompromised packageMalicious commit