Security researchers from Amazon Inspector uncovered a large-scale supply chain attack on the npm registry, identifying over 150,000 malicious packages linked to a coordinated token farming campaign associated with the tea.xyz protocol. Unlike traditional attacks that inject credential-stealing malware or ransomware, this campaign used self-replicating code to automatically generate and publish npm packages, exploiting the tea.xyz system to earn cryptocurrency rewards for the attackers. The malicious packages included tea.yaml files that connected them to attacker-controlled blockchain wallets, allowing the perpetrators to profit without the knowledge of legitimate developers or users.
This incident is considered one of the largest package flooding events in open source registry history, highlighting a shift in threat actor tactics toward financially motivated registry pollution at unprecedented scale. The attack was detected through a combination of advanced rule-based detection and AI, and the response involved rapid collaboration between Amazon Inspector and the Open Source Security Foundation (OpenSSF) to assign malicious package identifiers and coordinate mitigation. The event underscores the evolving risks in software supply chains and the necessity for industry-wide cooperation to defend against novel attack vectors driven by financial incentives.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
Follow-on reporting characterized the campaign as a worm-like or self-replicating attack that continuously published malicious npm packages designed to steal tokens and generate token-farming rewards. Multiple outlets reported that the activity was still not under control and represented a record-scale npm supply-chain incident.
Amazon Inspector reported detecting more than 150,000 malicious packages in the npm ecosystem tied to a large-scale token-farming campaign. The packages were described as part of a supply-chain abuse operation affecting the public registry.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcesocradar.io
Open sourcetheregister.com
Open sourcego.theregister.com
Open sourcecsoonline.com
Open sourcedarkreading.com
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.