A large-scale spam campaign has inundated the npm registry with over 46,000 fake packages, many of which use Indonesian names and food terms, and masquerade as Next.js projects. The campaign, active since early 2024, involved the systematic publication of these bogus packages from a small network of npm accounts, with the intent to flood the registry rather than to steal data or execute traditional malware. The packages contain a JavaScript file (such as auto.js or publishScript.js) that remains dormant unless manually executed, and there is no evidence of automatic execution during installation.
Further analysis suggests that the activity is likely the result of an outdated automation script originally tied to a cryptocurrency reward-farming project, rather than an active worm or exploit. The packages, which are mostly copies of a handful of base templates, have minimal download activity and currently pose little risk to users. However, the incident underscores the importance of maintaining strict dependency hygiene and monitoring for suspicious publication patterns in open-source ecosystems like npm.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Security reporting and research published on November 13, 2025 attributed the IndonesianFoods package flood to an automated abuse campaign designed to farm cryptocurrency-related rewards. The public disclosures established the incident as a large-scale npm ecosystem spam event.
The package-publishing activity expanded into a worm-like spam attack that rapidly pushed tens of thousands of fake packages to the npm registry. Reports described the scale as at least 46,000 packages, with some coverage placing the total near 100,000.
An automated package-publication operation using the 'IndonesianFoods' naming pattern began flooding the npm ecosystem with large numbers of packages. The activity was linked by researchers to a crypto reward-farming scheme rather than a conventional software supply-chain attack.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesnyk.io
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.