The Tea.xyz Token Farming Campaign is a threat campaign attributed to the Crims group, targeting the npm ecosystem by flooding the registry with over 150,000 packages designed to farm Tea.xyz (TEA) tokens.
The Tea.xyz Token Farming Campaign is a threat campaign attributed to the Crims group, targeting the npm ecosystem by flooding the registry with over 150,000 packages designed to farm Tea.xyz (TEA) tokens. The operation uses token-poisoning tactics to harvest TEA tokens when packages are installed, illustrating a high-impact supply-chain risk for JavaScript projects.
A coordinated token farming campaign has resulted in over 150,000 malicious packages flooding the npm registry, targeting the tea.xyz protocol. Discovered by Amazon Inspector researchers, this incident is described as…
Amazon Inspector has reported over 150,000 malicious packages in the npm registry linked to a token farming campaign targeting developers using the Tea Protocol. This incident is noted as one of the largest package…