Tea.xyz Token Farming Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 14, 2025
Last Seen
November 14, 2025

The Tea.xyz Token Farming Campaign is a threat campaign attributed to the Crims group, targeting the npm ecosystem by flooding the registry with over 150,000 packages designed to farm Tea.xyz (TEA) tokens.

Overview

The Tea.xyz Token Farming Campaign is a threat campaign attributed to the Crims group, targeting the npm ecosystem by flooding the registry with over 150,000 packages designed to farm Tea.xyz (TEA) tokens. The operation uses token-poisoning tactics to harvest TEA tokens when packages are installed, illustrating a high-impact supply-chain risk for JavaScript projects.

Related Threat Clusters

Recent Intelligence Reports

  • Crims flood npm with 150K+ junk packages to farm TEA tokens — Theregister · November 14, 2025
  • Crims poison 150K+ npm packages with token — Theregister · November 14, 2025
  • Amazon Inspector detects over 150,000 malicious packages linked to token farming campaign — Aws.Amazon · November 14, 2025

CVSS v3.1 Breakdown