Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in @akunsansan0/teagunup99 (npm)

@akunsansan0/teagunup99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Registry pollution; potential installation by developers unaware of malicious intent
Ecosystems
Attack vectors
Affected entities
  • @akunsansan0/teagunup99npm package containing autopublish scripts

@akunsansan0/teagunup99 is a malicious npm package identified as part of a coordinated campaign to flood the npm registry with reward-seeking packages. The package contains autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and republish derivative packages with randomized names, primarily Indonesian-themed variants.

The malicious payload modifies package.json to remove private flags and alter version numbers, enabling continuous republication of variants to the npm registry. This activity is designed to artificially inflate developer reputation scores for the tea.xyz token reward campaign.

The incident was identified by Amazon Inspector and credited to the OpenSSF's malicious-packages repository. The package represents a form of registry pollution attack that could deceive developers into installing malicious or unwanted packages.

Developers should remove this package and any derivatives from their dependencies and verify the integrity of their supply chains.

Indicators of compromise

Packages
  • @akunsansan0/teagunup99
Hashes
  • 600f602f58637605605e0442bd30114d39bba1a421144db96ecdfee03061e889

Remediation

  • Remove @akunsansan0/teagunup99 and any derivative packages from all dependencies
  • Audit npm package.json files for unexpected or unfamiliar packages with randomized or suspicious names
  • Review npm registry audit logs for any unauthorized package publications from compromised accounts
  • Use npm audit to identify and remove malicious packages from the dependency tree
  • Monitor for similar autopublish scripts in other packages, particularly those with Indonesian-themed or randomized naming patterns

Sources

  1. GitHub Advisory GHSA-2x3m-xq5x-jvpc · GitHub Advisory Database

Cite this entry

"Malicious code in @akunsansan0/teagunup99 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-teagunup99-npm-11ahtn

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/f-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g-web-components (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in @antv/dipper-hooks (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antstackio/shelbysam (npm)

    The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit