Feeds.Feedburner
Malicious NPM Packages Downloaded Over 86,000 Times in Spam Campaign
First seen 2 Dec 2025, 18:33 UTC
•
•7.5
Export
Article Content
Browse articles
A spam campaign has flooded the NPM repository with tens of thousands of malicious packages, likely orchestrated by an Indonesian threat actor. These packages, which have random names, can fetch dependencies from untrusted sites, posing risks to developers who download them.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
NPM Packages Distribute PylangGhost RAT in Supply Chain Attack