Skip to content
Malicious NPM Packages Downloaded Over 86,000 Times by Users

Malicious NPM Packages Downloaded Over 86,000 Times by Users

First seen 13 Nov 2025, 17:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A spam campaign involving tens of thousands of malicious NPM packages has been identified, likely orchestrated by an Indonesian threat actor. These packages, which have random names, can fetch dependencies from untrusted sites, posing risks to users who download them.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (2)