Feed
MediumPublished 25 Jul 202620 packages · 20 versions

GitHub Advisory npm CWE-506 backfill — 19 "John Wick 4" Spanish-SEO-spam autopublisher packages + `-pem-misa` tea.xyz farmer swept 2026-07-25 (all long-unpublished from npm)

Summary

On 2026-07-25 GitHub retired 20 npm CWE-506 malware advisories in a historical backfill batch — 19 SEO-spam autopublisher packages named after the 2023 movie "John Wick: Chapter 4" (all originally published 2023-03-23, unpublished 2023-03-27), plus -pem-misa@1.3.3 (published 2024-05-24, part of the Indonesian tea.xyz token-farming autopublisher wave). No credential-stealer or wallet-drain payload — these are token-farming and SEO-spam packages that have been off the public npm registry for 1-3 years.

obfuscation
Detected by
GitHub Advisory Database · OpenSSF Package Analysis · npm Security
Also known as
2026-07-25 GHSA npm tea.xyz historical backfill · John Wick 4 SEO spam cluster · Indonesian tea.xyz autopublisher wave
Ecosystems
npm
Packages tracked
20

What happened

On 2026-07-25 GitHub's Advisory Database added 20 new CWE-506 (Embedded Malicious Code) advisories against npm packages — all from an OpenSSF Package Analysis historical backfill import, not from a fresh attacker action on 2026-07-25. Two distinct clusters:

Cluster 1 — 2023 "John Wick: Chapter 4" Spanish-SEO-spam autopublisher (19 packages)

All 19 packages match the pattern of an autopublisher spamming npm with Spanish-language SEO-optimised movie-piracy prose in the package name itself. Verified against the public npm registry: package -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123 was created 2023-03-23 04:01:15 UTC at 1.0.0 and unpublished 2023-03-27 03:14:50 UTC — a ~4-day publish window. The other 18 sibling names in the sweep share the same March 2023 window and the same single-1.0.0-version signature.

Sample names in the cluster:

  • -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123
  • -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main
  • -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit
  • -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home
  • -john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love
  • -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love
  • -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-
  • -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol
  • -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena-
  • -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love
  • -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol
  • -john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love
  • -john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love
  • -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love
  • -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-
  • -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-
  • -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena-
  • -espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love
  • -espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love

Every name begins with a leading hyphen — an autopublisher signature. Legacy npm naming rules allowed leading hyphens (later restricted), and scammers exploited them for search-result reordering: names starting with - sort before names starting with alphanumerics on many display lists.

Cluster 2 — 2024 -pem-misa tea.xyz token farmer (1 package)

-pem-misa@1.3.3 was published 2024-05-24 17:12:17 UTC by npm account mipta19 (email miptaaaa19@gmail.com) advertising itself as "converting multiple words into an interesting sentence" under an ISC license. The package fits the fingerprint of the Indonesian tea.xyz token-farming autopublisher wave documented by Socket, Sonatype, Endor Labs, and Amazon in late 2025 through 2026:

  • Package package.json runs a script that clones itself with a randomly-generated Indonesian-themed name.
  • The clone strips the "private" flag, bumps the version, and republishes to inflate the account's tea.xyz-visible dependency count.
  • The tea.xyz protocol rewards project maintainers based on inbound dependency counts, so an autopublisher generating thousands of tiny cross-depending packages can farm rewards without any legitimate downstream usage.

Amazon researchers documented ~150,000 tea.xyz farmer packages in a single sweep in late 2025 (see Dark Reading, SecurityWeek, The Register write-ups); Socket followed up in early 2026 with "Another Round of TEA Protocol Spam Floods npm" characterising subsequent waves. -pem-misa is one entry in this long tail — GHSA is retroactively cataloguing it as CWE-506 on 2026-07-25.

Why this is a backfill, not a fresh attack

Three signals confirm this is a historical backfill import rather than a same-day attacker action:

  1. Package publish dates vs. GHSA advisory dates diverge by 1-3 years. The John Wick cluster was pushed to npm in March 2023 and unpublished within 4 days; -pem-misa was pushed in May 2024. All 21 GHSA advisories were dated 2026-07-25.
  2. All 21 packages are already unpublished from npm. Verified against the live npm registry — the John Wick names return unpublished / not-found and -pem-misa is no longer resolvable. A fresh attacker action would leave the tarball on the registry until npm security-replaced it.
  3. The cluster shape is consistent with an OpenSSF Package Analysis import. OpenSSF's malicious-packages repo commit log for 2026-07-25 shows a steady stream of "Ingest OSV" and "Assign IDs" commits — the pattern of a batch-import operation catching up on historical entries, not a coordinated take-down of a live attack.

Practical dependency-audit relevance

Essentially zero. Nobody legitimately depends on -john-wick-4-keanu-reeves-peliculas-completa-varindo-* or -pem-misa. The packages have been off the public registry for 1-3 years. A lockfile audit surfacing any of these names indicates either a very stale never-refreshed lockfile from 2023-2024 or a private-mirror leftover — both are curiosities rather than active-compromise incidents. This module exists to preserve audit-trail consistency with the other daily GHSA sweep modules and to document what GHSA published, not because a defender is at meaningful risk.

What was NOT in the 2026-07-25 batch

No credential-stealer, wallet-drain, or CI/CD-token-theft advisories were published on 2026-07-25 for any ecosystem — verified against the GHSA index for npm (only tea.xyz backfill above), PyPI (empty for that date; the previous PyPI sweep was the 10,000-package 2026-07-21 mass backfill), RubyGems (empty since the SleeperGem 2026-07-18 advisories), crates.io (empty since the 2026-07-18 OpenSSF typosquat burst), and NuGet (empty since the 2026-07-20 GHSA backfill sweep). Search-engine sweeps of Socket, Wiz, Snyk, JFrog, StepSecurity, and Aikido blogs (all blocked with 403 to WebFetch; queried via Google/Bing snippets and RSS-fallback chains) surfaced no new vendor disclosures dated 2026-07-25 or 2026-07-26 beyond the ongoing coverage of the pre-existing 2026-07-14 AsyncAPI compromise and 2026-07-11 Jscrambler compromise.

Affected packages (20)

  • npm-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena-
    1.0.0
  • npm-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-
    1.0.0
  • npm-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love
    1.0.0
  • npm-espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love
    1.0.0
  • npm-john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love
    1.0.0
  • npm-john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love
    1.0.0
  • npm-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love
    1.0.0
  • npm-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol
    1.0.0
  • npm-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love
    1.0.0
  • npm-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-
    1.0.0
  • npm-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol
    1.0.0
  • npm-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena-
    1.0.0
  • npm-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love
    1.0.0
  • npm-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-
    1.0.0
  • npm-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love
    1.0.0
  • npm-pem-misa
    1.3.3
  • npm-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123
    1.0.0
  • npm-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main
    1.0.0
  • npm-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit
    1.0.0
  • npm-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home
    1.0.0

Impact

  • These are historical backfill advisories, not fresh attacks — the packages were originally published in 2023 (John Wick cluster) and 2024 (-pem-misa), unpublished from npm within days to weeks, and GHSA is retroactively adding CWE-506 records on 2026-07-25 as part of an OpenSSF Package Analysis import batch
  • 19-package "John Wick: Chapter 4" Spanish-SEO-spam autopublisher cluster (all 1.0.0): package names encode Spanish-language "watch John Wick 4 full movie in HD online" prose (e.g. -john-wick-4-keanu-reeves-peliculas-completa-*, -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-*, -accion-pelicula-*, -espanol-*). Original publish window: 2023-03-23 04:01 UTC, unpublished 2023-03-27 03:14 UTC (~4 days on the registry). Every name starts with a leading hyphen — a classic autopublisher signature abusing npm's permissive naming rules to game search-result ordering
  • -pem-misa@1.3.3 (published 2024-05-24 17:12 UTC by npm account mipta19 / miptaaaa19@gmail.com) — the "tea protocol reward campaign" autopublisher pattern, later fingerprinted by Socket, Sonatype, Endor Labs, and Amazon in the 150,000-package tea.xyz token-farming worm write-ups of late 2025 through 2026. The -pem-misa variant is one of many Indonesian-authored autopublishers that modified package.json to strip the "private" flag, generated derivative packages with randomised Indonesian-themed names, and republished them to inflate the account's tea.xyz dependency count
  • None of the 20 packages are resolvable on the public npm registry as of 2026-07-25 — the John Wick cluster was unpublished in 2023 and -pem-misa was removed (either unpublished by the author or npm-security-removed) some time between 2024 and now. A lockfile hit on any of these names is extraordinarily unlikely (nobody legitimately depends on -john-wick-4-keanu-reeves-*), but the GHSA records now exist and any dependency-audit tooling that mirrors GHSA will start flagging them

What to do

  1. 1These advisories represent zero practical dependency-audit risk — the packages have been off the public npm registry for 1-3 years and would only appear in an extremely stale, never-updated lockfile
  2. 2If a lockfile audit does surface any of the John Wick names below, the presence is almost certainly a leftover from a 2023 auto-refresh that pulled the tarball into a private mirror before the 2023 unpublish — verify the mirror still serves it, purge if so, and rebuild the lockfile against the current public registry
  3. 3If you had -pem-misa in a lockfile: this is a tea.xyz autopublisher artifact — likely picked up via a dependency-refresh workflow that resolved a randomly-generated Indonesian-themed name. No credential-stealer payload has been documented for this specific package, but the pattern of package.json "private"-flag stripping and autorepublishing could interact with your build in unexpected ways. Remove from the lockfile and audit the human commit that added it
  4. 4For context on the tea.xyz farming pattern that spawned -pem-misa and thousands of similar Indonesian-authored autopublishers, see the Socket write-up "Another Round of TEA Protocol Spam Floods npm" and the Endor Labs "The Great Indonesian TEA Theft" analysis

References

npm-2026-07-25-ghsa-tea-xyz-backfill