ThreatCluster

Over 150,000 Malicious npm Packages Linked to Token Farming Campaign Detected

First seen 2 Dec 2025, 18:33 UTC Aws.AmazonTheregisterCsoonline 81% similarity 8

Article Content

Browse articles
ThreatCluster

Amazon Inspector has reported over 150,000 malicious packages in the npm registry linked to a token farming campaign targeting developers using the Tea Protocol. This incident is noted as one of the largest package flooding events in open source history, surpassing previous reports of 15,000 packages. The campaign was identified through advanced detection methods combining AI and rule-based analysis.

ThreatCluster AI How this analysis works

Community

Browse all →