Over 150,000 Malicious npm Packages Linked to Token Farming Campaign Detected
First seen 2 Dec 2025, 18:33 UTC
•

•81% similarity
•8
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Amazon Inspector has reported over 150,000 malicious packages in the npm registry linked to a token farming campaign targeting developers using the Tea Protocol. This incident is noted as one of the largest package flooding events in open source history, surpassing previous reports of 15,000 packages. The campaign was identified through advanced detection methods combining AI and rule-based analysis.
ThreatCluster AI
How this analysis works