Close Menu
Must Have Gadgets –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Google Calendar now lets you schedule tasks

    November 17, 2025

    Don’t like Liquid Glass? Updating to iOS 26.1 made a big difference for me – here’s how

    November 17, 2025

    Google is fighting the defamation battle Meta caved on

    November 17, 2025
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Trending
    • Google Calendar now lets you schedule tasks
    • Don’t like Liquid Glass? Updating to iOS 26.1 made a big difference for me – here’s how
    • Google is fighting the defamation battle Meta caved on
    • 3 reasons why your next monitor should be mini-LED
    • Amazon Slashed Lorcana Games and Accessories by Up to 50% This Black Friday
    • We hope Google takes a hint from this Apple phone case rumor
    • I’ve covered every Amazon Black Friday sale in Australia — these are 2025’s best LIVE deals
    • The 4 Things You Need for a Tech Bubble
    • Home
    • Shop
      • Earbuds & Headphones
      • Smartwatches
      • Mobile Accessories
      • Smart Home Devices
      • Laptops & Tablets
    • Gadget Reviews
    • How-To Guides
    • Mobile Accessories
    • Smart Devices
    • More
      • Top Deals
      • Smart Home
      • Tech News
      • Trending Tech
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Home»Mobile Accessories»Amazon researchers uncover major token farming malware scam – over 150,000 malicious packages found
    Mobile Accessories

    Amazon researchers uncover major token farming malware scam – over 150,000 malicious packages found

    adminBy adminNovember 17, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Amazon researchers uncover major token farming malware scam – over 150,000 malicious packages found
    Share
    Facebook Twitter LinkedIn Pinterest Email

    • Over 150,000 npm packages linked to a TEA token farming scheme were flagged by Amazon Inspector
    • Attackers used self-replicating spam packages to fake developer impact and earn crypto rewards
    • Researchers call it a major supply chain security event, urging stronger registry defenses and collaboration

    Researchers have found tens of thousands of self-replicating, yet seemingly pointless, npm packages, which appear to be part of a large-scale fraud operation looking to earn crypto tokens for the fraudsters.

    Cybersecurity researchers Endor Labs recently discovered more than 43,000 spam packages that apparently took two years, and at least 11 accounts, to upload. The packages, making up roughly 1% of the entire npm ecosystem, are not malicious in a traditional sense of the word – they’re not stealing data, providing a backdoor, or encrypting system files. They are, self-replicating when they’re downloaded and run.

    Endor speculated that they could be turned malicious via an update, but also said they could be a part of a financially motivated campaign, since some of the packages included tea.yaml files, listing TEA accounts.


    You may like

    Confirming the suspicions

    Tea is a decentralized framework protocol in which open source devs are rewarded when contributing software, meaning the attackers may have tried to fake their impact scores, thus earning more TEA tokens.

    Now, Amazon’s researchers have seemingly confirmed these suspicions. In a new report, the company said its Amazon Inspector (a security assessment service from AWS) was recently updated with a new detection rule, which flagged more than 150,000 packages linked to the tea.xyz token farming campaign – three times the size of the initial report.

    It took Amazon roughly a week to go from updating the detection rules, to discovering 150,000 packages, to validating the results with OpenSSF.

    “This is one of the largest package flooding incidents in open source registry history, and represents a defining moment in supply chain security,” Amazon explained.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    “This incident demonstrates both the evolving nature of threats where financial incentives drive registry pollution at unprecedented scale, and the critical importance of industry-community collaboration in defending the software supply chain.”

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

    Amazon farming major malicious malware packages Researchers Scam token Uncover
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    Amazon Slashed Lorcana Games and Accessories by Up to 50% This Black Friday

    November 17, 2025

    We hope Google takes a hint from this Apple phone case rumor

    November 17, 2025

    I’ve covered every Amazon Black Friday sale in Australia — these are 2025’s best LIVE deals

    November 17, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Google Calendar now lets you schedule tasks

    November 17, 2025

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    October 16, 2025

    The best AirPods deals for October 2025

    October 16, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    How-To Guides

    How to Disable Some or All AI Features on your Samsung Galaxy Phone

    By adminOctober 16, 20250
    Gadget Reviews

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    By adminOctober 16, 20250
    Smart Devices

    The best AirPods deals for October 2025

    By adminOctober 16, 20250

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Latest Post

    Google Calendar now lets you schedule tasks

    November 17, 2025

    Don’t like Liquid Glass? Updating to iOS 26.1 made a big difference for me – here’s how

    November 17, 2025

    Google is fighting the defamation battle Meta caved on

    November 17, 2025
    Recent Posts
    • Google Calendar now lets you schedule tasks
    • Don’t like Liquid Glass? Updating to iOS 26.1 made a big difference for me – here’s how
    • Google is fighting the defamation battle Meta caved on
    • 3 reasons why your next monitor should be mini-LED
    • Amazon Slashed Lorcana Games and Accessories by Up to 50% This Black Friday

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 must-have-gadgets.

    Type above and press Enter to search. Press Esc to cancel.