Feed
HighPublished 7 Sept 2026186 packages · 186 versions

GitHub Advisory malware sweep - 2026-09-06/07 alphabetical E-range backfill: tea.xyz `eka-*` Indonesian-food autopublish flood (~100 pkgs), `eigenstate-*` tea.xyz self-replicating spam (~15 pkgs), z3n research-pattern `effective_/efficient_<animal>_z3n` spam (~35 pkgs), and misc E-prefix opportunistic drops

Summary

Yesterday's (Sept 6) sweep captured 13 npm items; the queue then flushed ~200 more, mostly published as of 2026-09-06 and continuing into 2026-09-07. Three coherent clusters (tea.xyz eka-<indonesian-food><N>-<suffix> autopublish, tea.xyz eigenstate-<astronomy>-<tech>-<lib> autopublish, and effective_/efficient_<animal>_z3n research spam) plus a long tail of misc E-prefix drops.

typosquatdependency-confusioncredential-theftobfuscation
Detected by
GitHub Advisory Database · OpenSSF malicious-packages · OpenSSF Package Analysis · Amazon Inspector
Also known as
2026-09-07 GHSA E-range mass backfill · tea.xyz eka-* Indonesian-food autopublish flood · tea.xyz eigenstate-* astronomy-lib autopublish flood · z3n research spam effective_/efficient_<animal>_z3n
Ecosystems
npm
Packages tracked
186

What happened

Between roughly 2026-09-06 00:00 and 2026-09-07 08:00 UTC, GitHub Advisory Database flushed a large alphabetical backfill of malicious-package advisories in the e- prefix range. Yesterday's (Sept 6) ingest ran before this queue drained and captured only the first 13; the rest (~200 more) landed after and are catalogued here. Four coherent clusters emerge:

Cluster A - tea.xyz eka-<indonesian-food><N>-<suffix> autopublish flood

Naming template: eka-<food><N>-<tag> with food ∈ {enting, empal, esdoger, brongkos, bubursumsum, dodol, donat, buburayam, dradag, bakwan, brengkes, botok, bakso, bika, bubur, asinan} (all Indonesian dishes / snacks / drinks), N ∈ 1-100, tag ∈ {breki, sluey, ruro, sukiwir, miaww, kuki, kyuki, pore, sumpek, apidev, riris}.

GHSA metadata verbatim: "This package appears to be part of the tea.xyz token reward campaign that flooded npm. The package contains autopublish scripts designed to automatically generate and publish derivative packages with randomized names to artificially inflate developer reputation scores for tea protocol token rewards. The malware modifies package.json files, removes private flags, alters version numbers, generates random Indonesian-themed and English package names, and continuously republishes variants to pollute the npm registry."

Sampled GHSA advisories: GHSA-rppw-gq7q-4v3m (eka-enting87-breki), GHSA-fq2f-vpxp-rmj6 (eka-empal42-sukiwir), GHSA-fjhh-fr66-j7p3 (eka-empal81-kyuki), GHSA-p8xp-vqhv-j4c4 (eka-esdoger53-breki), GHSA-fgjm-wcg2-xqg7 (eka-brongkos29-sluey), GHSA-72xh-8mhp-xhrp (eka-empal71-ruro), and ~90 more under the same template.

Cluster B - tea.xyz eigenstate-<astronomy><tech><lib> autopublish spam

Naming template: eigenstate-<astro-term>-<tech-fragment>-<lib> blending astronomy terms (parallax, ophiuchus, procyon, auriga, deneb, alphard, hermes, spectron, gravitationalwave, wormhole, singularitarianism, areology, archaeogenetics, outercore, bionics) with tech-lib fragments (chromedriver, socketio, electron-builder, electron-lithosphere, config-ora, module, init, test, javascript, technocracy, despina).

Same tea.xyz autopublish description as Cluster A - different template, same operator pattern.

Sampled GHSA advisories: GHSA-xq8g-m5c6-6m24 (eigenstate-gravitationalwave-config-ora), GHSA-7cg9-4wqc-3vqg (eigenstate-ophiuchus-sociobiology-koa), GHSA-wrwf-w7jm-gw84 (eigenstate-auriga-module-chromedriver), GHSA-2cpr-h94x-qprf (eigenstate-parallax-init-miranda), GHSA-3mxp-qpcq-fg64 (eigenstate-spectron-loopback-wormhole), GHSA-rp54-9fmm-3p28 (eigenstate-outercore-procyon-colors), GHSA-rvjf-x2pj-6cj9 (eigenstate-archaeogenetics-singularitarianism-socketio), GHSA-9prv-62qg-qv48 (eigenstate-electron-builder-despina-bionics).

Cluster C - z3n research-pattern effective_/efficient_<animal>_z3n spam

Naming template: {effective|efficient}_<animal>_z3n (animals include orangutan, monkey, termite, chickadee, ostrich, ptarmigan, spoonbill, aphid, scallop, lungfish, penguin, landfowl, moth, rabbit, grouse, duck, tarantula, tiger, hare, lemur, python, takin, guineafowl, butterfly, starfish, meadowlark). Variants swap the _z3n suffix for _dumbs, _0xrequest, or a color-modifier tag (efficient_gerbil_white-13, efficient_catfish_chocolate-98, efficient_macaw_moccasin-85, efficient_duck_emerald-86).

Boilerplate CWE-506 "malicious code" description on each; this template has appeared in earlier 2026 sweeps and is consistent with a single OSS-research group's registry-pollution testing rather than active exploitation.

Cluster D - Sept 6-7 misc E-prefix opportunistic drops

Mixed opportunistic drops carrying the more serious GHSA full-compromise boilerplate ("any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer"). Names split into two sub-groups:

Corporate-namespace / ecosystem impersonators (the dep-confusion probes worth manual triage):

| Package | Ecosystem hook | |---|---| | egjs-cli | egjs (NAVER open-source UI framework) | | ejson2env | Shopify EJSON tooling | | ejson-rails | Ruby-on-Rails / Shopify EJSON | | ejs-client | EJS template engine | | egg-plugin-knex | eggjs Node framework + knex ORM | | egg-arbitrary | eggjs Node framework | | effector-kws | Effector state manager | | effector-react-kws | Effector + React binding | | eip-119-json-provider | Ethereum EIP-119 wallet-connect RPC | | efx-angular-components | Corporate Angular UI namespace | | eg-affiliates-common / eg-affiliates-common-test | Affiliate-tooling internal namespace | | eg4-fangfa | Chinese enterprise namespace | | egov-pep-frontend | E-government / PEP-check frontend | | egs-trusted-domains | Trust-store / SSO tooling | | egstore-ctx / egstore-query / egstore-carousel / egstore-graphql-client / egstore-suspense | egstore frontend framework family | | ein-services / ein-loader | EIN tax-ID / internal service naming | | einthyra-notthedevs | Impersonator of an unnamed vendor | | einfprog | German intro-to-programming coursepack | | einkaufen | German-language shopping SDK impersonator | | eithernet / eithernet-test / eithernet-test-fixtures / eithernet-test-fixtures-test | ethernet-typosquat family | | ehance-assistant / ehance-assistant33 | Vendor-name typosquat | | ehouse, eh-fiddle, eflectron, eficsi, efp9 | Misc opportunistic drops | | eganglia | Ganglia monitoring impersonator | | egret_moccasin-14 | Egret game engine + color-tag operator suffix | | egis-tsc | Egis vendor + TypeScript compiler tag | | eggcoin / eggdrop | Crypto / IRC name grab | | eggplant-umbrella-aig1 / eggplant-juniper-lcjd / eggplant-radish-ka52 / eggplant-delta-8omx | Eggplant test-automation vendor typosquats | | eight-spend-men, eighster, eimearmartin, eimearobrien, eikasia, ejercico, ejungle, ejstags | Misc / individual-name grabs |

Random-string opportunistic drops (grep-only): ejrfsqmkdconukbl, ejdgrvaqkioslhbf, ejbwdr-devapptea, eikpndvxbtfhkcas, ehquvdznyglmrpxb, ehxjimturwyqnzbk, eivybsafunmzpxlg, eixp4ressz, egnxaqfzbjhdlvkp, egmoizjqkvybsulc, egudkjkpcrwhlfvy.

Distinction from npm-2026-09-07-coinbase-base-cb-wallet-dep-confusion

The Coinbase / Base / SCW dep-confusion drop published the same day (2026-09-07) is a completely separate cluster: single-operator, 13 packages, all named to shadow Coinbase internal namespaces. That is a targeted campaign catalogued in its own module. This sweep covers the alphabetical E-prefix backfill and tea.xyz reward spam - registry-pollution rather than a targeted campaign.

Registry state

All packages listed below are flagged as malware on npm and quarantined. Private mirrors (Verdaccio, Artifactory, Nexus) that cached tarballs before quarantine will keep serving them - explicit deny-listing of the eka- / eigenstate- name prefixes, the _z3n suffix, and the individual misc names is the durable mitigation.

Discovery credits

GitHub Advisory Database (all advisories published 2026-09-06 and 2026-09-07), OpenSSF malicious-packages, OpenSSF Package Analysis, Amazon Inspector (source for the tea.xyz Cluster B advisories).

Affected packages (186)

These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.

Impact

  • Cluster A - tea.xyz eka-<indonesian-food><N>-<suffix> autopublish flood (~100 packages, all versions): GHSA description on each explicitly reads "part of the tea.xyz token reward campaign that flooded npm" - autopublish scripts modify package.json, strip private flags, bump versions, generate random Indonesian-food + English/random-word package names, and republish variants to inflate developer reputation for tea protocol token rewards. Name shape: eka-<food><N>-<tag> where food ∈ {enting, empal, esdoger, brongkos, bubursumsum, dodol, donat, buburayam, dradag, bakwan, brengkes, botok, bakso, bika, bubur, asinan}, N ∈ 1-100, tag ∈ {breki, sluey, ruro, sukiwir, miaww, kuki, kyuki, pore, sumpek, apidev, riris}. Low real-lockfile probability but registry pollution is severe
  • Cluster B - tea.xyz eigenstate-<astronomy><tech><lib> autopublish spam (~15 packages, all versions): same tea.xyz reward pattern, different naming template. Multi-word chained names blending astronomy terms (parallax, ophiuchus, procyon, auriga, deneb, alphard, hermes, spectron, singularitarianism, gravitationalwave, wormhole) with tech-lib fragments (chromedriver, socketio, electron-builder, electron-lithosphere, config-ora, module, init, test, javascript). Each carries the same tea.xyz autopublish disclosure in GHSA description. Same low real-lockfile probability but higher visual-legitimacy risk
  • Cluster C - z3n research-pattern effective_<animal>_z3n / efficient_<animal>_z3n (~35 packages, all versions): uniform naming template {effective|efficient}_<animal>_z3n (animals: orangutan, monkey, termite, chickadee, ostrich, ptarmigan, spoonbill, aphid, scallop, lungfish, penguin, landfowl, moth, rabbit, grouse, duck, tarantula, tiger, hare, lemur, python, takin, guineafowl, butterfly, starfish, meadowlark, brown-quail, yellow-mole, jade-mackerel) plus adjective-color variants (efficient_gerbil_white-13, efficient_catfish_chocolate-98, efficient_macaw_moccasin-85, efficient_duck_emerald-86) and _dumbs / _0xrequest operator suffixes. Boilerplate CWE-506 "malicious code"; matches the z3n OSS research pattern flagged earlier in 2026. Very low real-lockfile probability
  • Cluster D - Sept 6-7 misc E-prefix opportunistic drops (~50 packages, all versions): mixed opportunistic drops carrying the full-compromise boilerplate ("any computer that has this package installed or running should be considered fully compromised"). Names include ecosystem-adjacent hooks (egjs-cli, ejson2env, ejson-rails, ejs-client, egg-plugin-knex, egg-arbitrary, effector-kws, effector-react-kws, eip-119-json-provider), corporate-namespace impersonators (efx-angular-components, eg-affiliates-common, eg-affiliates-common-test, eg4-fangfa, egov-pep-frontend, egs-trusted-domains, egstore-ctx, egstore-query, egstore-carousel, egstore-graphql-client, egstore-suspense, ein-services, ein-loader, einthyra-notthedevs, einfprog, einkaufen, eithernet, eithernet-test, eithernet-test-fixtures, eithernet-test-fixtures-test, efx-angular-components, ehance-assistant, ehance-assistant33, ehouse, eh-fiddle, eflectron, eficsi, efp9, eganglia, egret_moccasin-14, egis-tsc, eggcoin, eggdrop, eggplant-umbrella-aig1, eggplant-juniper-lcjd, eggplant-radish-ka52, eggplant-delta-8omx, eight-spend-men, eighster, eight-spend-men, eimearmartin, eimearobrien, eikasia, ejercico, ejungle, ejstags, ejrfsqmkdconukbl, ejdgrvaqkioslhbf, ejbwdr-devapptea, eikpndvxbtfhkcas, ehquvdznyglmrpxb, ehxjimturwyqnzbk, eivybsafunmzpxlg, eixp4ressz, egnxaqfzbjhdlvkp, egmoizjqkvybsulc, egudkjkpcrwhlfvy). Any lockfile hit is a real compromise; the corporate-namespace names in particular (egov-pep-frontend, egstore-*, ein-services, eip-119-json-provider, egg-plugin-knex) are the ones most likely to be resolved as dep-confusion probes

What to do

  1. 1Grep every package-lock.json, yarn.lock, pnpm-lock.yaml, and package.json in your org for the names listed below. Uninstall on hit and rebuild the lockfile against a clean cache
  2. 2*For Cluster A (`eka- tea.xyz Indonesian-food autopublish)** and **Cluster B (eigenstate-` tea.xyz astronomy-lib autopublish)*: these are registry-pollution / reputation-mining spam - low real-user probability. Block the eka- and eigenstate- name prefixes on internal Verdaccio / Artifactory / Nexus mirrors to prevent future re-uploads under the same pattern. No host-side forensics required unless a lockfile actually references one
  3. 3*For Cluster C (`effective__z3n / efficient__z3n`)*: research-pattern spam - block the _z3n suffix on internal mirrors and grep for the exact names listed below
  4. 4For Cluster D (misc E-prefix opportunistic drops): on any lockfile hit, treat the resolving host as fully compromised (per GHSA boilerplate) - rotate every credential the host had access to (npm tokens, SSH keys, cloud IAM, git, SSO), reimage where practical. Focus manual triage on the corporate-namespace names (egov-pep-frontend, egstore-*, ein-services, ein-loader, eip-119-json-provider, egg-plugin-knex, egg-arbitrary, efx-angular-components) - these are the dep-confusion probes most likely to hit real internal-namespace resolution
  5. 5For every npm install in CI, prefer --ignore-scripts to block postinstall payloads. Cluster D is where this matters most - Clusters A/B/C are registry-pollution rather than install-time-execution
  6. 6Consider adding all four cluster name prefixes (eka-, eigenstate-, _z3n suffix, and the individual misc names) to a private-registry deny-list until further vendor triage exists

References

multi-2026-09-07-ghsa-malware-sweep