GitHub Advisory npm CWE-506 backfill — 19 "John Wick 4" Spanish-SEO-spam autopublisher packages + `-pem-misa` tea.xyz farmer swept 2026-07-25 (all long-unpublished from npm)
On 2026-07-25 GitHub retired 20 npm CWE-506 malware advisories in a historical backfill batch — 19 SEO-spam autopublisher packages named after the 2023 movie "John Wick: Chapter 4" (all originally published 2023-03-23, unpublished 2023-03-27), plus -pem-misa@1.3.3 (published 2024-05-24, part of the Indonesian tea.xyz token-farming autopublisher wave). No credential-stealer or wallet-drain payload — these are token-farming and SEO-spam packages that have been off the public npm registry for 1-3 years.
- Detected by
- GitHub Advisory Database · OpenSSF Package Analysis · npm Security
- Also known as
- 2026-07-25 GHSA npm tea.xyz historical backfill · John Wick 4 SEO spam cluster · Indonesian tea.xyz autopublisher wave
- Ecosystems
- npm
- Packages tracked
- 20
What happened
On 2026-07-25 GitHub's Advisory Database added 20 new CWE-506 (Embedded Malicious Code) advisories against npm packages — all from an OpenSSF Package Analysis historical backfill import, not from a fresh attacker action on 2026-07-25. Two distinct clusters:
Cluster 1 — 2023 "John Wick: Chapter 4" Spanish-SEO-spam autopublisher (19 packages)
All 19 packages match the pattern of an autopublisher spamming npm with Spanish-language SEO-optimised movie-piracy prose in the package name itself. Verified against the public npm registry: package -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123 was created 2023-03-23 04:01:15 UTC at 1.0.0 and unpublished 2023-03-27 03:14:50 UTC — a ~4-day publish window. The other 18 sibling names in the sweep share the same March 2023 window and the same single-1.0.0-version signature.
Sample names in the cluster:
-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home-john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena--john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena--john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol-john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena--accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena--accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena--espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love-espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love
Every name begins with a leading hyphen — an autopublisher signature. Legacy npm naming rules allowed leading hyphens (later restricted), and scammers exploited them for search-result reordering: names starting with - sort before names starting with alphanumerics on many display lists.
Cluster 2 — 2024 -pem-misa tea.xyz token farmer (1 package)
-pem-misa@1.3.3 was published 2024-05-24 17:12:17 UTC by npm account mipta19 (email miptaaaa19@gmail.com) advertising itself as "converting multiple words into an interesting sentence" under an ISC license. The package fits the fingerprint of the Indonesian tea.xyz token-farming autopublisher wave documented by Socket, Sonatype, Endor Labs, and Amazon in late 2025 through 2026:
- Package
package.jsonruns a script that clones itself with a randomly-generated Indonesian-themed name. - The clone strips the
"private"flag, bumps the version, and republishes to inflate the account's tea.xyz-visible dependency count. - The tea.xyz protocol rewards project maintainers based on inbound dependency counts, so an autopublisher generating thousands of tiny cross-depending packages can farm rewards without any legitimate downstream usage.
Amazon researchers documented ~150,000 tea.xyz farmer packages in a single sweep in late 2025 (see Dark Reading, SecurityWeek, The Register write-ups); Socket followed up in early 2026 with "Another Round of TEA Protocol Spam Floods npm" characterising subsequent waves. -pem-misa is one entry in this long tail — GHSA is retroactively cataloguing it as CWE-506 on 2026-07-25.
Why this is a backfill, not a fresh attack
Three signals confirm this is a historical backfill import rather than a same-day attacker action:
- Package publish dates vs. GHSA advisory dates diverge by 1-3 years. The John Wick cluster was pushed to npm in March 2023 and unpublished within 4 days;
-pem-misawas pushed in May 2024. All 21 GHSA advisories were dated 2026-07-25. - All 21 packages are already unpublished from npm. Verified against the live npm registry — the John Wick names return unpublished / not-found and
-pem-misais no longer resolvable. A fresh attacker action would leave the tarball on the registry until npm security-replaced it. - The cluster shape is consistent with an OpenSSF Package Analysis import. OpenSSF's
malicious-packagesrepo commit log for 2026-07-25 shows a steady stream of "Ingest OSV" and "Assign IDs" commits — the pattern of a batch-import operation catching up on historical entries, not a coordinated take-down of a live attack.
Practical dependency-audit relevance
Essentially zero. Nobody legitimately depends on -john-wick-4-keanu-reeves-peliculas-completa-varindo-* or -pem-misa. The packages have been off the public registry for 1-3 years. A lockfile audit surfacing any of these names indicates either a very stale never-refreshed lockfile from 2023-2024 or a private-mirror leftover — both are curiosities rather than active-compromise incidents. This module exists to preserve audit-trail consistency with the other daily GHSA sweep modules and to document what GHSA published, not because a defender is at meaningful risk.
What was NOT in the 2026-07-25 batch
No credential-stealer, wallet-drain, or CI/CD-token-theft advisories were published on 2026-07-25 for any ecosystem — verified against the GHSA index for npm (only tea.xyz backfill above), PyPI (empty for that date; the previous PyPI sweep was the 10,000-package 2026-07-21 mass backfill), RubyGems (empty since the SleeperGem 2026-07-18 advisories), crates.io (empty since the 2026-07-18 OpenSSF typosquat burst), and NuGet (empty since the 2026-07-20 GHSA backfill sweep). Search-engine sweeps of Socket, Wiz, Snyk, JFrog, StepSecurity, and Aikido blogs (all blocked with 403 to WebFetch; queried via Google/Bing snippets and RSS-fallback chains) surfaced no new vendor disclosures dated 2026-07-25 or 2026-07-26 beyond the ongoing coverage of the pre-existing 2026-07-14 AsyncAPI compromise and 2026-07-11 Jscrambler compromise.
Affected packages (20)
- npm
-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena-1.0.0 - npm
-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-1.0.0 - npm
-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0 - npm
-espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0 - npm
-john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0 - npm
-john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love1.0.0 - npm
-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love1.0.0 - npm
-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol1.0.0 - npm
-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love1.0.0 - npm
-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-1.0.0 - npm
-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol1.0.0 - npm
-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena-1.0.0 - npm
-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0 - npm
-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-1.0.0 - npm
-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0 - npm
-pem-misa1.3.3 - npm
-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-1231.0.0 - npm
-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main1.0.0 - npm
-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit1.0.0 - npm
-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home1.0.0
Impact
- These are historical backfill advisories, not fresh attacks — the packages were originally published in 2023 (John Wick cluster) and 2024 (
-pem-misa), unpublished from npm within days to weeks, and GHSA is retroactively adding CWE-506 records on 2026-07-25 as part of an OpenSSF Package Analysis import batch - 19-package "John Wick: Chapter 4" Spanish-SEO-spam autopublisher cluster (all
1.0.0): package names encode Spanish-language "watch John Wick 4 full movie in HD online" prose (e.g.-john-wick-4-keanu-reeves-peliculas-completa-*,-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-*,-accion-pelicula-*,-espanol-*). Original publish window: 2023-03-23 04:01 UTC, unpublished 2023-03-27 03:14 UTC (~4 days on the registry). Every name starts with a leading hyphen — a classic autopublisher signature abusing npm's permissive naming rules to game search-result ordering -pem-misa@1.3.3(published 2024-05-24 17:12 UTC by npm accountmipta19/miptaaaa19@gmail.com) — the "tea protocol reward campaign" autopublisher pattern, later fingerprinted by Socket, Sonatype, Endor Labs, and Amazon in the 150,000-package tea.xyz token-farming worm write-ups of late 2025 through 2026. The-pem-misavariant is one of many Indonesian-authored autopublishers that modifiedpackage.jsonto strip the"private"flag, generated derivative packages with randomised Indonesian-themed names, and republished them to inflate the account's tea.xyz dependency count- None of the 20 packages are resolvable on the public npm registry as of 2026-07-25 — the John Wick cluster was unpublished in 2023 and
-pem-misawas removed (either unpublished by the author or npm-security-removed) some time between 2024 and now. A lockfile hit on any of these names is extraordinarily unlikely (nobody legitimately depends on-john-wick-4-keanu-reeves-*), but the GHSA records now exist and any dependency-audit tooling that mirrors GHSA will start flagging them
What to do
- 1These advisories represent zero practical dependency-audit risk — the packages have been off the public npm registry for 1-3 years and would only appear in an extremely stale, never-updated lockfile
- 2If a lockfile audit does surface any of the John Wick names below, the presence is almost certainly a leftover from a 2023 auto-refresh that pulled the tarball into a private mirror before the 2023 unpublish — verify the mirror still serves it, purge if so, and rebuild the lockfile against the current public registry
- 3If you had
-pem-misain a lockfile: this is a tea.xyz autopublisher artifact — likely picked up via a dependency-refresh workflow that resolved a randomly-generated Indonesian-themed name. No credential-stealer payload has been documented for this specific package, but the pattern ofpackage.json"private"-flag stripping and autorepublishing could interact with your build in unexpected ways. Remove from the lockfile and audit the human commit that added it - 4For context on the tea.xyz farming pattern that spawned
-pem-misaand thousands of similar Indonesian-authored autopublishers, see the Socket write-up "Another Round of TEA Protocol Spam Floods npm" and the Endor Labs "The Great Indonesian TEA Theft" analysis
References
- GitHubGitHub Advisory Database — recent npm malware advisoriesgithub.com
- GitHubGHSA-fffx-vm7c-rv7c — -pem-misa tea.xyz farmer advisorygithub.com
- GitHubGHSA-cjrq-9724-p6c3 — -whare-to-watch-john-wick... representative SEO-spam advisorygithub.com
- SocketAnother Round of TEA Protocol Spam Floods npm, But It's Not a Wormsocket.dev
- Endor LabsThe Great Indonesian TEA Theft: Analyzing a NPM Spam Campaignendorlabs.com
- SecurityWeekAmazon Detects 150,000 NPM Packages in Worm-Powered Campaignsecurityweek.com
- OpenSSFOpenSSF Malicious Packages Repositorygithub.com