Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena- (npm)
Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on download count and deployment scope
- Ecosystems
- Attack vectors
- Affected entities
- -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena-
A malicious npm package named "-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena-" was published to the npm registry. The package name uses a deceptive naming scheme referencing a movie title, a common tactic in typosquatting and social engineering attacks targeting developers.
The malicious package was identified and documented by the OpenSSF's malicious packages project, which maintains a public database of confirmed malicious software supply chain incidents. The incident was assigned identifier MAL-2024-1688.
The package was published on the npm registry and has since been addressed through removal or quarantine. The OpenSSF database serves as a reference for the security community to track and prevent installation of such packages.
Indicators of compromise
- Packages
- -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena-
Remediation
- Remove the package from any environments where it may have been installed
- Audit npm package.lock or yarn.lock files for any references to this package
- Review any systems that may have executed code from this package for signs of compromise
- Use npm audit or similar tools to detect and prevent installation of known malicious packages
- Consider using package allowlists or private registries to control which packages can be installed
Sources
- GitHub Advisory GHSA-3qf6-jx77-xmgw · GitHub Advisory Database
Cite this entry
"Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena- (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 25, 2026; last updated July 25, 2026. https://supplychainattack.org/incident/malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varind-a271jg
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)
Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and documented by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)
A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)
Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malicious code in -pem-misa (npm)
The npm package -pem-misa contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.
npmCompromised packageMalicious commit