🛡️ MAL-2025-129955 — rude-turkey-z3n
Description
Malicious code in rude_turkey_z3n (npm) ## Source: amazon-inspector This package appears to be part of the tea.xyz token reward campaign that flooded npm. These packages typically contain autopublish scripts (auto.js, autopublish.js, autopublish2.js, autopublish3.js) designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The malicious payload modifies package.json to remove private flags, changes version numbers, generates random Indonesian-themed package names (some variants are also in English), and continuously republishes variants to pollute the npm registry.
Affected software and timeline
Affected software: rude-turkey-z3n. Published on 11 November 2025. No public exploit is currently recorded for this entry. Record sourced from OSV.
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| rude-turkey-z3n | — | — |
References
N/AFree Vulnerability Check
Is your site affected by MAL-2025-129955?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2025-129955 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.