IndonesianFoods Campaign is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 13, 2025; most recent activity November 13, 2025.
IndonesianFoods is a worm-based threat campaign targeting the Node.js/npm ecosystem by rapidly publishing a large volume of packages. The campaign demonstrates automated propagation at scale, potentially delivering malicious code or dependencies and eroding trust in the npm registry, highlighting a significant supply-chain risk for JavaScript projects.
A large-scale spam campaign, known as the IndonesianFoods worm, has inundated the npm registry with over 100,000 spam packages. This campaign, which has been ongoing for more than two years, utilizes at least 11…
A malware campaign has been identified that utilizes malicious npm packages to create fake websites designed to identify and exploit potential victims. The threat actor, known as 'dino_reborn', published these packages…