IndonesianFoods Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 13, 2025
Last Seen
November 13, 2025

IndonesianFoods Campaign is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 13, 2025; most recent activity November 13, 2025.

Overview

IndonesianFoods is a worm-based threat campaign targeting the Node.js/npm ecosystem by rapidly publishing a large volume of packages. The campaign demonstrates automated propagation at scale, potentially delivering malicious code or dependencies and eroding trust in the npm registry, highlighting a significant supply-chain risk for JavaScript projects.

Related Threat Clusters

  • IndonesianFoods Worm Floods npm with Over 100,000 Spam Packages

    A large-scale spam campaign, known as the IndonesianFoods worm, has inundated the npm registry with over 100,000 spam packages. This campaign, which has been ongoing for more than two years, utilizes at least 11…

    4 articles · Updated November 13, 2025
  • Malicious npm Packages Use Adspect Cloaking in Crypto Scam

    A malware campaign has been identified that utilizes malicious npm packages to create fake websites designed to identify and exploit potential victims. The threat actor, known as 'dino_reborn', published these packages…

    13 articles · Updated November 18, 2025

Recent Intelligence Reports

  • New ‘IndonesianFoods’ worm floods npm with 100,000 packages — Bleepingcomputer · November 13, 2025

CVSS v3.1 Breakdown