Amazon researchers uncover major token farming malware scam – over 150,000 malicious packages found

  • Over 150,000 npm packages linked to a TEA token farming scheme were flagged by Amazon Inspector
  • Attackers used self-replicating spam packages to fake developer impact and earn crypto rewards
  • Researchers call it a major supply chain security event, urging stronger registry defenses and collaboration

Researchers have found tens of thousands of self-replicating, yet seemingly pointless, npm packages, which appear to be part of a large-scale fraud operation looking to earn crypto tokens for the fraudsters.

Cybersecurity researchers Endor Labs recently discovered more than 43,000 spam packages that apparently took two years, and at least 11 accounts, to upload. The packages, making up roughly 1% of the entire npm ecosystem, are not malicious in a traditional sense of the word – they’re not stealing data, providing a backdoor, or encrypting system files. They are, self-replicating when they’re downloaded and run.

Endor speculated that they could be turned malicious via an update, but also said they could be a part of a financially motivated campaign, since some of the packages included tea.yaml files, listing TEA accounts.

Confirming the suspicions

Tea is a decentralized framework protocol in which open source devs are rewarded when contributing software, meaning the attackers may have tried to fake their impact scores, thus earning more TEA tokens.

Now, Amazon’s researchers have seemingly confirmed these suspicions. In a new report, the company said its Amazon Inspector (a security assessment service from AWS) was recently updated with a new detection rule, which flagged more than 150,000 packages linked to the tea.xyz token farming campaign – three times the size of the initial report.

It took Amazon roughly a week to go from updating the detection rules, to discovering 150,000 packages, to validating the results with OpenSSF.

“This is one of the largest package flooding incidents in open source registry history, and represents a defining moment in supply chain security,” Amazon explained.

“This incident demonstrates both the evolving nature of threats where financial incentives drive registry pollution at unprecedented scale, and the critical importance of industry-community collaboration in defending the software supply chain.”

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Oregon’s Attorney General withdraws effort to delay Paramount and Warner Bros. merger

Oregon Attorney General Dan Rayfield had been seeking documents from Paramount related to its takeover of Warner Bros. Discovery. Rayfield also asked a state...

ICE are heavily armed killers. They’re also huge losers

Federal agents patrol the halls of immigration court at the Jacob K. Javits Federal Building in December 2025. | Photo by Michael Nigro/Pacific Press/LightRocket...

White House taps the guy who keeps crying ‘aliens’ to run UFO group

Harvard astrophysicist Avi Loeb will head the UAP Science Advisory Council established by the White House, the Pentagon, the Office of the Director of...

Nintendo’s Talking Flower got a small price cut

If you’re the type of person who could always use a little extra positive affirmation, or you have a weakness for weird gadgets, the...

FL Studio head Constantin Koehncke turns to Reddit for feedback and fun

If you're a music maker of a certain age, then you probably once dabbled with a pirated copy of a little app called Fruity...

The perfect kit for all your tiny repairs

Hi, friends! Welcome to Installer No. 135, your guide to the best and Verge-iest stuff in the world. (If you're new here, welcome, crank...

A tasty RPG that will make you very hungry

Roleplaying games are often defined by excess. Storylines that span dozens of hours, side quests so big they could be their own game, massive...

Are you filthy enough for a $700 portable shower? 

A luxurious hot shower anywhere you go. Hot showers, like electricity, are a luxury that's easy to take for granted. That all changes after a...

Apple sues OpenAI for allegedly stealing hardware secrets

Apple has sued OpenAI, alleging that engineers stole Apple secrets to advance the AI startup's hardware plans. In its complaint, Apple says it uncovered...

The FCC is cracking down on DJI tech that dodged the foreign drone ban

The Xtra Muse and the DJI Osmo Pocket 3. | Photo by Sean Hollister / The Verge Last year, we told you about Xtra, the...