IndonesianFoods Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 13, 2025
Last Seen
November 16, 2025

Related Threat Clusters

  • Logitech Data Leak Following Zero-Day Attack

    Logitech experienced a data leak due to a zero-day attack. The incident has raised concerns about the security of user data and the company's response to vulnerabilities. The US Senate has been pressing for a report on…

    2 articles · Updated November 16, 2025
  • Logitech Data Leak Following Zero-Day Attack

    Logitech experienced a data leak due to a zero-day attack, impacting user data security. The incident has drawn attention from the US Senate, particularly Senator Ron Wyden, who has been advocating for better…

    2 articles · Updated November 16, 2025
  • IndonesianFoods Worm Infects npm with Over 44,000 Malicious Packages

    A large-scale spam campaign known as the IndonesianFoods worm has targeted the npm ecosystem, deploying over 43,000 malicious packages across at least 11 user accounts. This attack, which has been ongoing for more than…

    2 articles · Updated November 13, 2025
  • IndonesianFoods Worm Floods npm with Over 100,000 Spam Packages

    A large-scale spam campaign, known as the IndonesianFoods worm, has inundated the npm registry with over 100,000 spam packages. This campaign, which has been ongoing for more than two years, utilizes at least 11…

    4 articles · Updated November 13, 2025
  • Malicious npm Packages Use Adspect Cloaking in Crypto Scam

    A malware campaign has been identified that utilizes malicious npm packages to create fake websites designed to identify and exploit potential victims. The threat actor, known as 'dino_reborn', published these packages…

    13 articles · Updated November 18, 2025
  • Over 150,000 Malicious npm Packages Flood Registry in Token Farming Attack

    A coordinated token farming campaign has resulted in over 150,000 malicious packages flooding the npm registry, targeting the tea.xyz protocol. Discovered by Amazon Inspector researchers, this incident is described as…

    5 articles · Updated November 15, 2025
  • Over 150,000 Malicious npm Packages Linked to Token Farming Campaign Detected

    Amazon Inspector has reported over 150,000 malicious packages in the npm registry linked to a token farming campaign targeting developers using the Tea Protocol. This incident is noted as one of the largest package…

    4 articles · Updated November 15, 2025

Recent Intelligence Reports

  • Logitech leaks data after zero-day attack — Theregister · November 16, 2025
  • Logitech leaks data after zero — Theregister · November 16, 2025
  • Worm flooding npm registry with token stealers still isn’t under control — Csoonline · November 15, 2025
  • New ‘IndonesianFoods’ worm floods npm with 100,000 packages — Bleepingcomputer · November 13, 2025
  • “IndonesianFoods” npm Worm Publishes 44,000 Malicious Packages — Infosecurity-Magazine · November 13, 2025

CVSS v3.1 Breakdown