- A two-year coordinated campaign flooded npm with more than 43,000 hidden spam packets
- Some packages include worm-like scripts that automatically create and publish new entries.
- Attackers can fake TEA influence points to get rewards from decentralized developers
About 1% of the entire NPM ecosystem now consists of fake inactive packages that were uploaded as part of a year-long targeted (and potentially malicious) campaign, experts say.
Cybersecurity researcher Endor Labs discovered more than 43,000 spam packets that took nearly two years to download in a coordinated effort that required at least 11 individual user accounts.
“Packages were systematically released over a long period of time, filling the NPM registry with unwanted packages that persisted in the ecosystem for almost two years,” the researchers said.
TEA Token Harvest?
The researchers named the company Indonesian Foods because of the name of the packages. The malicious script used for naming has two internal dictionaries, one with Indonesian names and the other with Indonesian food terms. When the script runs, it randomly selects two terms, adds a number and a suffix.
The surprising thing is that the packages themselves are not malicious. They are not designed to steal sensitive data from developers and do not serve as backdoors. Instead, they sit idle collecting downloads.
The researchers explained that some packages have thousands of downloads per week, giving an attacker a potential advantage: “This gives attackers the opportunity to perform a malicious attack in the future that affects all of these downloads.”
Some packages contained a worm-like script that, when executed, spawned and created additional scripts that were then added to npm.
Aside from its malicious potential, researchers believe it could be part of a financially motivated campaign. Apparently, some packages included a tea.yaml file containing a list of TEA accounts. Tea is a decentralized infrastructure protocol where open source developers are rewarded when they contribute software.
This could mean that the attackers tried to cheat their influence score, thus earning more TEA tokens.
through Hacker news
The best antivirus for any budget
Follow TechRadar on Google News I Add us as your preferred source Get our news, reviews and expert opinions in your feed. Don’t forget to click the follow button!
And, of course, you can Siga TechRadar on TikTok For news, reviews, unboxing videos and our regular updates WhatsApp very

