Thousands of fake packages flood npm registry in major attack – here’s what we know


  • Over 43,000 dormant spam packages flooded npm in a coordinated two-year campaign
  • Some packages contained worm-like scripts that automatically generated and published new records
  • Attackers may have falsified TEA impact scores to earn decentralized developer rewards

About 1% of the entire npm ecosystem now consists of fake, dormant packages that were uploaded as part of a years-long targeted – and potentially malicious – campaign, experts have claimed.

Cybersecurity researchers Endor Labs discovered more than 43,000 spam packets that took nearly two years to upload in a coordinated effort that took at least 11 different user accounts to retrieve.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top