Tea.xyz Protocol — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 14, 2025
Last Seen
November 14, 2025

Tea.xyz Protocol is a technology platform tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 14, 2025; most recent activity November 14, 2025.

Overview

Tea.xyz Protocol is a technology platform linked to a large-scale token farming campaign that targeted the npm ecosystem, resulting in the publication of over 150,000 malicious npm packages. The operation demonstrates automated, mass-distribution capability aimed at harvesting tokens or credentials from developers, highlighting a significant supply-chain risk in software dependencies.

Related Threat Clusters

Recent Intelligence Reports

  • 150,000 Packages Flood NPM Registry in Token Farming Campaign — Darkreading · November 14, 2025
  • Amazon Inspector detects over 150,000 malicious packages linked to token farming campaign — Aws.Amazon · November 14, 2025

CVSS v3.1 Breakdown