Crims poison 150K+ npm packages with token-farming malware

go.theregister.com/feed/www.theregister.com/2025/11/14/selfreplicating_supplychain_attack_poisons_150k

Amazon spilled the TEA
Yet another supply chain attack has hit the npm registry in what Amazon describes as "one of the largest package flooding incidents in open source registry history" - but with a twist. Instead of injecting credential-stealing code or ransomware into the packages,…

This story appeared on go.theregister.com, 2025-11-14 18:22:47.
The Entire Business World on a Single Page. Free to Use →