Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

How Fake Font Packages Abused npm as a CDN

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Henrik Plate
Word Count
1,244
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

Between mid-December and late January, a significant abuse of the npm registry occurred when four accounts published over 100 packages masquerading as benign but embedding large volumes of encrypted data disguised as WOFF2 font files, leading to approximately 34 TiB of uploaded data and an estimated 4.3 PiB of downloads. While the packages contained no malicious code, analysis revealed they were not real fonts but data chunks, with some versions showing HLS playlists pointing to encrypted media segments, suggesting misuse for content distribution. The accounts have since been removed, yet this incident highlights a systemic issue within open-source infrastructure like npm, which operates on limited resources and relies heavily on responsible use and community support. It underscores concerns that unchecked abuse, rather than malware, poses a significant threat to the sustainability and reliability of open-source ecosystems, as these platforms are often run by non-profits or small teams with limited funding and rely on the responsible use of shared resources by the community.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Vector Search 1 1,668 286 111 +15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.