GitHub Advisory npm CWE-506 backfill - 19 "John Wick 4" Spanish-SEO-spam autopublisher packages + `-pem-misa` tea.xyz farmer swept 2026-07-25 (all long-unpublished from npm)
On 2026-07-25 GitHub retired 20 npm CWE-506 malware advisories in a historical backfill batch - 19 SEO-spam autopublisher packages named after the 2023 movie "John Wick: Chapter 4" (all originally published 2023-03-23, unpublished 2023-03-27), plus -pem-misa@1.3.3 (published 2024-05-24, part of the Indonesian tea.xyz token-farming autopublisher wave). No credential-stealer or wallet-drain payload - these are token-farming and SEO-spam packages that have been off the public npm registry for 1-3 years.
Versions named here: 1.3.3