
- Over 43,000 dormant spam packages flooded npm in a coordinated two-year campaign
- Some packages contained worm-like scripts that auto-generated and published new entries
- Attackers may have faked TEA impact scores to earn decentralized developer rewards
Roughly 1% of the entire npm ecosystem now consists of bogus, dormant packages that were uploaded as part of a years-long targeted - and potentially malicious - campaign, experts have claimed.