Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @akunsansan0/teaguntur99 (npm)

@akunsansan0/teaguntur99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Registry pollution and reputation score manipulation; potential impact on developers who installed the package or its auto-generated derivatives.
Ecosystems
Attack vectors
Affected entities
  • @akunsansan0/teaguntur99Malicious npm package containing autopublish scripts

@akunsansan0/teaguntur99 is a malicious npm package identified as part of the tea.xyz token reward campaign that flooded npm with fraudulent packages. The package contains autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) designed to automatically generate and publish derivative packages with randomized names.

The malicious payload modifies package.json to remove private flags and changes version numbers, then generates random Indonesian-themed and English-themed package names. The scripts continuously republish variants to pollute the npm registry and artificially inflate developer reputation scores for tea protocol token rewards.

This incident was identified by Amazon Inspector and credited to the OpenSSF malicious-packages repository. The attack represents a systematic attempt to manipulate the npm ecosystem for financial gain through token reward schemes.

Indicators of compromise

Packages
  • @akunsansan0/teaguntur99

Remediation

  • Remove @akunsansan0/teaguntur99 and any auto-generated derivative packages from your dependencies
  • Audit npm package.json and lock files for any suspicious or unfamiliar packages with randomized names
  • Review npm account activity and publishing history for unauthorized package publications
  • Monitor for and remove any packages generated by the autopublish scripts from the registry
  • Update to a clean version of your project dependencies from a known-good state

Sources

  1. GitHub Advisory GHSA-7vrx-gxgf-9x88 · GitHub Advisory Database

Cite this entry

"Malicious code in @akunsansan0/teaguntur99 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2025; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-teaguntur99-npm-14inrx

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in ezdiscordbots (npm)

    The npm package ezdiscordbots contained malicious code that executes with root privileges during installation. A postinstall script runs obfuscated JavaScript that decodes to attacker-controlled payload and installs a persistent Linux daemon via the node-linux dependency.

    npmCompromised packageMalicious commit
  2. resolvedcritical

    Malicious code in alipclutch-baileys (npm)

    The npm package alipclutch-baileys contained obfuscated malicious code that exfiltrated session state and message data to an attacker-controlled domain (fiora.nixel.my.id) during normal message-send operations. The malicious code was embedded in lib/Socket/messages-send.js using character-code obfuscation to evade detection.

    npmCompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in encrypt-string-safe (npm)

    The npm package encrypt-string-safe contains malicious obfuscated code that fetches and executes attacker-controlled JavaScript from a lookalike CDN (npm.jsdelivree.com) via plain HTTP. Any invocation of the package's exported APIs triggers remote code execution in the caller's process.

    npmCompromised packageMalicious commit
  4. activecritical

    Malicious code in @cliphijack/santaclaude (npm)

    The npm package @cliphijack/santaclaude contains malicious code that establishes a persistent WebSocket connection to a remote server, enabling remote code execution, privilege escalation via sudo manipulation, and vendor-controlled auto-updates. The package grants the attacker persistent root access and the ability to remotely control a local Claude Code TUI instance.

    npmCompromised packageMalicious commit