Tea.xyz Protocol is a technology platform tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 14, 2025; most recent activity November 14, 2025.
Tea.xyz Protocol is a technology platform linked to a large-scale token farming campaign that targeted the npm ecosystem, resulting in the publication of over 150,000 malicious npm packages. The operation demonstrates automated, mass-distribution capability aimed at harvesting tokens or credentials from developers, highlighting a significant supply-chain risk in software dependencies.
A coordinated token farming campaign has resulted in over 150,000 malicious packages flooding the npm registry, targeting the tea.xyz protocol. Discovered by Amazon Inspector researchers, this incident is described as…
Amazon Inspector has reported over 150,000 malicious packages in the npm registry linked to a token farming campaign targeting developers using the Tea Protocol. This incident is noted as one of the largest package…