Skip to content

Malicious code in allied-white-pike (npm)

Malware Published Aug 31, 2026 to the GitHub Advisory Database • Updated Aug 31, 2026

Package

npm allied-white-pike (npm)

Affected versions

> 0

Patched versions

None

Description

Source: amazon-inspector (754d317760eb54bbdc048bb90476a7077188e5a263c14dc577b74fad76fcb151)

This package appears to be part of the tea.xyz token reward campaign that flooded npm. These packages typically contain autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The malicious payload modifies package.json to remove private flags, changes version numbers, generates random Indonesian-themed package names (some variants are also in English), and continuously republishes variants to pollute the npm registry.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Aug 31, 2026
Reviewed Aug 31, 2026
Last updated Aug 31, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-v7jp-hmqx-8pj3

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.