Thousands of fake packages flood npm registry in major attack – here’s what we know



  • More than 43,000 inactive spam packages flooded npm in a coordinated two-year campaign
  • Some packages contained worm-like scripts that automatically generated and published new entries.
  • Attackers may have faked TEA impact scores to obtain rewards from decentralized developers

About 1% of the entire npm ecosystem now consists of fake, inactive packages that were uploaded as part of a targeted (and potentially malicious) campaign that lasted for years, experts said.

Cybersecurity researchers Endor Labs discovered more than 43,000 spam packets that took almost two years to load in a coordinated effort that required at least 11 different user accounts to do so.



Leave a Comment

Your email address will not be published. Required fields are marked *