Malicious code in @akunsansan0/tea_guntry99 (npm)
@akunsansan0/tea_guntry99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
- Disclosed
- Last updated
- Blast radius
- Registry-wide pollution; affects npm ecosystem integrity and developer trust
- Ecosystems
- Attack vectors
- Affected entities
- @akunsansan0/tea_guntry99Malicious npm package containing autopublish scripts
@akunsansan0/tea_guntry99 is a malicious npm package identified as part of a coordinated campaign to flood the npm registry with reward-seeking packages. The package contains autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and republish derivative packages with randomized names, primarily using Indonesian-themed naming conventions.
The malicious payload modifies package.json to remove private flags and alter version numbers, enabling continuous republication of variants to the npm registry. This attack vector is designed to artificially inflate developer reputation scores within the tea.xyz token reward protocol.
The campaign represents a systematic attempt to pollute the npm registry and compromise its integrity by leveraging automated publishing mechanisms. The attack was identified and credited to the OpenSSF's malicious-packages repository.
Developers should remove this package and any derivative packages generated by its autopublish scripts from their dependencies immediately.
Indicators of compromise
- Packages
- @akunsansan0/tea_guntry99
Remediation
- Remove @akunsansan0/tea_guntry99 and all derivative packages from npm dependencies
- Audit npm package.json and lock files for any packages with randomized or suspicious names published around the same timeframe
- Review npm account activity logs for unauthorized package publications
- Report any discovered derivative packages to npm security team
- Consider using npm audit and supply chain security tools to detect similar malicious packages
Sources
- GitHub Advisory GHSA-jr8r-fpq3-wq7v · GitHub Advisory Database
Cite this entry
"Malicious code in @akunsansan0/tea_guntry99 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tea-guntry99-npm-105u64
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/f-wx (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-web-components (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/dipper-hooks (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antstackio/shelbysam (npm)
The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.
Shai-HuludnpmCompromised packageMalicious commit