Malicious code in @akunsansan0/tea_gunt99 (npm)
@akunsansan0/tea_gunt99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.
- Disclosed
- Last updated
- Blast radius
- Registry pollution and reputation score manipulation; potential impact on developers who installed the package
- Ecosystems
- Attack vectors
- Affected entities
- @akunsansan0/tea_gunt99npm package containing malicious autopublish scripts
The package @akunsansan0/tea_gunt99 was identified as part of a coordinated campaign to flood npm with malicious packages related to the tea.xyz token reward program. The package contains autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that execute automatically upon installation.\n\nThe malicious payload modifies package.json to remove private flags and alter version numbers, then generates random package names (primarily Indonesian-themed variants, with some English variants) and continuously republishes them to the npm registry. This behavior is designed to artificially inflate developer reputation scores for tea protocol token rewards.\n\nThe incident represents a form of registry pollution and supply chain manipulation targeting the npm ecosystem. The package was identified and documented by the OpenSSF's malicious-packages project.\n\nAs of the advisory publication date (2026-07-26), the malicious package has been identified and documented, indicating the threat has been contained and addressed by the registry and security community.
Indicators of compromise
- Packages
- @akunsansan0/tea_gunt99
Remediation
- Remove @akunsansan0/tea_gunt99 and any derivative packages generated by its autopublish scripts from your project dependencies
- Audit npm audit logs and package-lock.json for any unexpected package installations or version changes
- Review and update any projects that may have installed this package to ensure no malicious code remains
- Monitor for and remove any derivative packages with randomized names that may have been published as a result of this malicious activity
- Report any suspicious packages to npm security team
Sources
- GitHub Advisory GHSA-w4v7-hwhv-m755 · GitHub Advisory Database
Cite this entry
"Malicious code in @akunsansan0/tea_gunt99 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tea-gunt99-npm-opu2qa
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/f-wx (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-web-components (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/dipper-hooks (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antstackio/shelbysam (npm)
The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.
Shai-HuludnpmCompromised packageMalicious commit