Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedhigh

Malicious code in @akunsansan0/tehpucuk3 (npm)

@akunsansan0/tehpucuk3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Registry pollution; potential installation by developers unaware of malicious intent
Ecosystems
Attack vectors
Affected entities
  • @akunsansan0/tehpucuk3

@akunsansan0/tehpucuk3 is a malicious npm package identified as part of the tea.xyz token reward campaign that flooded npm with fraudulent packages. The package contains autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) that execute automatically upon installation.\n\nThe malicious payload modifies package.json to remove private flags, alters version numbers, and generates random package names (primarily Indonesian-themed variants, with some English variants) to create derivative packages. These variants are then continuously republished to the npm registry, causing widespread registry pollution.\n\nThe attack is designed to artificially inflate developer reputation scores within the tea protocol ecosystem, enabling attackers to claim token rewards. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages repository.\n\nDevelopers who installed this package may have unknowingly contributed to registry pollution and fraudulent token claims.

Indicators of compromise

Packages
  • @akunsansan0/tehpucuk3

Remediation

  • Remove @akunsansan0/tehpucuk3 and any derivative packages from your project dependencies immediately
  • Audit your npm account and publishing history for unauthorized package publications
  • Review package.json and lock files for unexpected changes or new dependencies
  • Check npm registry for any packages you did not intentionally publish
  • Report any unauthorized packages to npm security team
  • Use npm audit to scan for known malicious packages
  • Consider using package allow-lists or private registries to prevent installation of untrusted packages

Sources

  1. GitHub Advisory GHSA-pjq9-gjj5-57w2 · GitHub Advisory Database

Cite this entry

"Malicious code in @akunsansan0/tehpucuk3 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tehpucuk3-npm-184qwn

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in @akunsansan0/tea_nextgun (npm)

    @akunsansan0/tea_nextgun is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards.

    npmMalicious commit
  2. containedcritical

    Malicious code in @antv/f-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in @antv/g-web-components (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/dipper-hooks (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit