Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

Thousands of fake packages flood npm registry in major attack - here's what we know

Cyber security Cloud computing blue abstract digital binary code background. Innovative technology and Artificial intelligence concept. New futuristic system technology symbol. Vector illustration.
  • Over 43,000 dormant spam packages flooded npm in a coordinated two-year campaign
  • Some packages contained worm-like scripts that auto-generated and published new entries
  • Attackers may have faked TEA impact scores to earn decentralized developer rewards

Roughly 1% of the entire npm ecosystem now consists of bogus, dormant packages that were uploaded as part of a years-long targeted - and potentially malicious - campaign, experts have claimed.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.