Malicious NPM Packages Downloaded Over 86,000 Times in Spam Campaign

Malicious NPM Packages Downloaded Over 86,000 Times in Spam Campaign

First seen 2 Dec 2025, 18:33 UTC ArstechnicaFeeds.Feedburner 7.5

Article Content

Browse articles
ThreatCluster

A spam campaign has flooded the NPM repository with tens of thousands of malicious packages, likely orchestrated by an Indonesian threat actor. These packages, which have random names, can fetch dependencies from untrusted sites, posing risks to developers who download them.