150,000 Packages Flood NPM Registry in Token Farming Campaign
ID: c3db977f-fd88-5e92-b599-e984c85b3d12
STIX ID: report--c3db977f-fd88-5e92-b599-e984c85b3d12
Feed Name: Dark Reading
Amazon Inspector researchers discovered a large-scale token-farming campaign that created more than 150,000 non-functional NPM packages linked to the tea.xyz rewards protocol. The attackers used automated tooling and circular dependency chains to self-replicate packages and inflate tea.xyz scoring, causing supply-chain pollution, infrastructure strain, and financial extraction without deploying traditional malware; Amazon and OpenSSF assigned MAL-IDs and recommended detection, auditing, and SBOM/CI/CD hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
