Malicious code in @akunsansan0/susu9 (npm)
@akunsansan0/susu9 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
- Disclosed
- Last updated
- Blast radius
- Registry pollution; potential impact on developers who installed this package or its auto-generated derivatives.
- Ecosystems
- Attack vectors
- Affected entities
- @akunsansan0/susu9npm package containing malicious autopublish scripts
@akunsansan0/susu9 is a malicious npm package identified as part of a coordinated campaign to flood the npm registry with packages designed to game the tea.xyz token reward system. The package contains autopublish scripts (such as auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and publish derivative packages with randomized names, primarily using Indonesian-themed naming conventions alongside English variants.\n\nThe malicious payload modifies package.json to remove private flags and alter version numbers, enabling continuous republication of variants to the npm registry. This attack vector inflates developer reputation scores within the tea protocol ecosystem while simultaneously polluting the public npm registry with unwanted packages.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks such coordinated supply chain attacks. The package has been flagged with identifier MAL-2025-181344.
Indicators of compromise
- Packages
- @akunsansan0/susu9
Remediation
- Remove @akunsansan0/susu9 and any auto-generated derivative packages from your project dependencies
- Audit npm audit logs and package-lock.json for any installations of this package or related variants
- Review and update npm security policies to detect and block packages with autopublish or auto-generation scripts
- Monitor for similar patterns in the tea.xyz token reward campaign packages
- Report any discovered variants to the OpenSSF malicious-packages repository
Sources
- GitHub Advisory GHSA-gqx4-r9r4-w5w7 · GitHub Advisory Database
Cite this entry
"Malicious code in @akunsansan0/susu9 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu9-npm-19ex0m
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in @akunsansan0/tea_nextgun (npm)
@akunsansan0/tea_nextgun is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards.
npmMalicious commit - containedcritical
Malicious code in @antv/f-wx (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-web-components (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/dipper-hooks (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit