Amazon researchers uncover major token farming malware scam – over 150,000 malicious packages found


  • Over 150,000 npm packages linked to a TEA token farming scheme were flagged by Amazon Inspector
  • Attackers used self-replicating spam packages to fake developer influence and earn crypto rewards
  • Researchers are calling it a major supply chain security event that calls for stronger registry defenses and collaboration

Researchers have found tens of thousands of self-replicating, but seemingly pointless, npm packages that appear to be part of a large-scale fraud operation seeking to earn crypto tokens for the fraudsters.

Cybersecurity researchers Endor Labs recently discovered more than 43,000 spam packets that apparently took two years and at least 11 accounts to upload. The packages, which make up about 1% of the entire npm ecosystem, are not malicious in a traditional sense of the word – they do not steal data, provide a backdoor, or encrypt system files. They are self-replicating when downloaded and run.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top