Skip to content
Malicious NPM Packages Downloaded Over 86,000 Times in Spam Campaign

Malicious NPM Packages Downloaded Over 86,000 Times in Spam Campaign

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A spam campaign has flooded the NPM repository with tens of thousands of malicious packages, likely orchestrated by an Indonesian threat actor. These packages, which have random names, can fetch dependencies from untrusted sites, posing risks to developers who download them.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)