Amazon Flags 150,000 npm Packages in Token Farming Malware Scheme
First seen 11 Jan 2026, 09:34 UTC
•
•27
Export
Article Content
Browse articles
Amazon researchers identified a significant token farming malware scam involving over 150,000 npm packages. The attackers utilized self-replicating spam packages to exploit the npm ecosystem for cryptocurrency tokens. This discovery highlights the ongoing challenges in securing package management systems against malicious activities.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
NPM Packages Distribute PylangGhost RAT in Supply Chain Attack