logo

150,000 Packages Flood NPM Registry in Token Farming Campaign

ID: c3db977f-fd88-5e92-b599-e984c85b3d12

STIX ID: report--c3db977f-fd88-5e92-b599-e984c85b3d12

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-11-14

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Amazon Inspector researchers discovered a large-scale token-farming campaign that created more than 150,000 non-functional NPM packages linked to the tea.xyz rewards protocol. The attackers used automated tooling and circular dependency chains to self-replicate packages and inflate tea.xyz scoring, causing supply-chain pollution, infrastructure strain, and financial extraction without deploying traditional malware; Amazon and OpenSSF assigned MAL-IDs and recommended detection, auditing, and SBOM/CI/CD hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.