Thousands of fake packages flood npm registry in major attack – here’s what we know



  • Over 43,000 dormant spam packages flooded npm in a coordinated two-year campaign
  • Some packages contained worm-like scripts that auto-generated and published new entries
  • Attackers may have faked TEA impact scores to earn decentralized developer rewards

Roughly 1% of the entire npm ecosystem now consists of bogus, dormant packages that were uploaded as part of a years-long targeted – and potentially malicious – campaign, experts have claimed.

Cybersecurity researchers Endor Labs discovered more than 43,000 spam packages which took almost two years to upload in a coordinated effort that took at least 11 distinct user accounts to pull off.





Source link

The post Thousands of fake packages flood npm registry in major attack – here’s what we know first appeared on TechToday.

This post originally appeared on TechToday.

Leave a Reply

Your email address will not be published. Required fields are marked *