Malicious code in @akunsansan0/tehpucuk1 (npm)
@akunsansan0/tehpucuk1 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
- Disclosed
- Last updated
- Blast radius
- npm registry; developers who installed this package or its derivative variants
- Ecosystems
- Attack vectors
- Affected entities
- @akunsansan0/tehpucuk1Malicious npm package containing autopublish scripts
@akunsansan0/tehpucuk1 is a malicious npm package identified as part of a coordinated campaign to flood the npm registry with packages designed to game the tea.xyz token reward system. The package contains autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that automatically generate and publish derivative packages with randomized names, primarily using Indonesian-themed naming conventions alongside English variants.
The malicious payload modifies package.json files to remove private flags and alter version numbers, enabling continuous republication of variants to the npm registry. This activity is designed to artificially inflate developer reputation scores and claim token rewards from the tea protocol initiative.
The package was identified through Amazon Inspector and reported by the OpenSSF's malicious-packages project. This represents part of a broader pattern of abuse targeting npm's registry infrastructure and the tea protocol's incentive mechanisms.
Indicators of compromise
- Packages
- @akunsansan0/tehpucuk1
Remediation
- Remove @akunsansan0/tehpucuk1 and any derivative packages from your dependencies immediately
- Audit your npm install history and package-lock.json for any variants of this package or related malicious packages from the tea.xyz campaign
- Review your npm account for any unauthorized package publications or modifications
- Monitor your projects for unexpected package.json modifications or autopublish behavior
- Report any discovered variants to the OpenSSF malicious-packages project and npm security team
Sources
- GitHub Advisory GHSA-5x43-hcjm-x76h · GitHub Advisory Database
Cite this entry
"Malicious code in @akunsansan0/tehpucuk1 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tehpucuk1-npm-scvv98
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in ezdiscordbots (npm)
The npm package ezdiscordbots contained malicious code that executes with root privileges during installation. A postinstall script runs obfuscated JavaScript that decodes to attacker-controlled payload and installs a persistent Linux daemon via the node-linux dependency.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in alipclutch-baileys (npm)
The npm package alipclutch-baileys contained obfuscated malicious code that exfiltrated session state and message data to an attacker-controlled domain (fiora.nixel.my.id) during normal message-send operations. The malicious code was embedded in lib/Socket/messages-send.js using character-code obfuscation to evade detection.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in encrypt-string-safe (npm)
The npm package encrypt-string-safe contains malicious obfuscated code that fetches and executes attacker-controlled JavaScript from a lookalike CDN (npm.jsdelivree.com) via plain HTTP. Any invocation of the package's exported APIs triggers remote code execution in the caller's process.
npmCompromised packageMalicious commit - activecritical
Malicious code in @cliphijack/santaclaude (npm)
The npm package @cliphijack/santaclaude contains malicious code that establishes a persistent WebSocket connection to a remote server, enabling remote code execution, privilege escalation via sudo manipulation, and vendor-controlled auto-updates. The package grants the attacker persistent root access and the ability to remotely control a local Claude Code TUI instance.
npmCompromised packageMalicious commit