Close Menu
Must Have Gadgets –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The 8 Black Friday deals I hope to see in 2025

    November 13, 2025

    Anthropic details how it measures Claude’s wokeness

    November 13, 2025

    8 Things We Liked About ‘Bat-Fam’ and 2 Things We Didn’t

    November 13, 2025
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Trending
    • The 8 Black Friday deals I hope to see in 2025
    • Anthropic details how it measures Claude’s wokeness
    • 8 Things We Liked About ‘Bat-Fam’ and 2 Things We Didn’t
    • Look at how thin the Galaxy S26 Edge could have been
    • Don’t risk it — get your annual antivirus coverage for less than $25 with these Black Friday deals
    • One of my favorite Dell laptops is now on sale and it’s $430 cheaper than when I gave it 4.5-stars
    • Smartphones are getting thinner and lighter — and the iPhone 18 Pro Max may go the other direction
    • Evacuation Warnings Issued as Atmospheric River Threatens to Drench Burn-Scarred Los Angeles
    • Home
    • Shop
      • Earbuds & Headphones
      • Smartwatches
      • Mobile Accessories
      • Smart Home Devices
      • Laptops & Tablets
    • Gadget Reviews
    • How-To Guides
    • Mobile Accessories
    • Smart Devices
    • More
      • Top Deals
      • Smart Home
      • Tech News
      • Trending Tech
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Home»Top Deals»Thousands of fake packages flood npm registry in major attack – here’s what we know
    Top Deals

    Thousands of fake packages flood npm registry in major attack – here’s what we know

    adminBy adminNovember 13, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Thousands of fake packages flood npm registry in major attack – here’s what we know
    Share
    Facebook Twitter LinkedIn Pinterest Email

    • Over 43,000 dormant spam packages flooded npm in a coordinated two-year campaign
    • Some packages contained worm-like scripts that auto-generated and published new entries
    • Attackers may have faked TEA impact scores to earn decentralized developer rewards

    Roughly 1% of the entire npm ecosystem now consists of bogus, dormant packages that were uploaded as part of a years-long targeted – and potentially malicious – campaign, experts have claimed.

    Cybersecurity researchers Endor Labs discovered more than 43,000 spam packages which took almost two years to upload in a coordinated effort that took at least 11 distinct user accounts to pull off.

    “The packages were systematically published over an extended period, flooding the npm registry with junk packages that survived in the ecosystem for almost two years,” the researchers said.


    You may like

    TEA token harvesting?

    The researchers dubbed the campaign IndonesianFoods because of the way the packages are named. The malicious script used for naming contains two internal dictionaries, one with Indonesian names, and other with Indonesian food terms. When the script runs, it selects two terms at random, adds a number, and appends a suffix.

    The strange part is that the packages themselves are not malicious. They’re not designed to steal sensitive developer data, or to act as a backdoor. Instead, they just lie there, dormant, gathering downloads.

    Some packages have thousands of weekly downloads, the researchers explain, hinting that it gives the attacker a potential edge: “This leaves an opportunity for the attackers to push a malicious commit in the future that would affect all those downloads.”

    Some of the packages did contain a worm-like script which, if run, would generate and create additional scripts which would then be added to npm.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Besides malicious potential, the researchers also believe this could be a part of a financially motivated campaign. Apparently, some of the packages included tea.yaml files, listing TEA accounts. Tea is a decentralized framework protocol in which open source devs are rewarded when contributing software.

    This could mean that the attackers tried to fake their impact scores, thus earning more TEA tokens.

    Via The Hacker News

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

    attack Fake Flood heres major NPM packages registry Thousands
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    Don’t risk it — get your annual antivirus coverage for less than $25 with these Black Friday deals

    November 13, 2025

    Prime Members Can Snag 43% Off the Already Affordable Robot Vac Before Black Friday

    November 13, 2025

    The hottest Samsung phones are all at massive discounts!

    November 13, 2025
    Leave A Reply Cancel Reply

    Top Posts

    The 8 Black Friday deals I hope to see in 2025

    November 13, 2025

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    October 16, 2025

    The best AirPods deals for October 2025

    October 16, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    How-To Guides

    How to Disable Some or All AI Features on your Samsung Galaxy Phone

    By adminOctober 16, 20250
    Gadget Reviews

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    By adminOctober 16, 20250
    Smart Devices

    The best AirPods deals for October 2025

    By adminOctober 16, 20250

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Latest Post

    The 8 Black Friday deals I hope to see in 2025

    November 13, 2025

    Anthropic details how it measures Claude’s wokeness

    November 13, 2025

    8 Things We Liked About ‘Bat-Fam’ and 2 Things We Didn’t

    November 13, 2025
    Recent Posts
    • The 8 Black Friday deals I hope to see in 2025
    • Anthropic details how it measures Claude’s wokeness
    • 8 Things We Liked About ‘Bat-Fam’ and 2 Things We Didn’t
    • Look at how thin the Galaxy S26 Edge could have been
    • Don’t risk it — get your annual antivirus coverage for less than $25 with these Black Friday deals

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 must-have-gadgets.

    Type above and press Enter to search. Press Esc to cancel.