How Fake Font Packages Abused npm as a CDN
Blog post from Endor Labs
Between mid-December and late January, a significant abuse of the npm registry occurred when four accounts published over 100 packages masquerading as benign but embedding large volumes of encrypted data disguised as WOFF2 font files, leading to approximately 34 TiB of uploaded data and an estimated 4.3 PiB of downloads. While the packages contained no malicious code, analysis revealed they were not real fonts but data chunks, with some versions showing HLS playlists pointing to encrypted media segments, suggesting misuse for content distribution. The accounts have since been removed, yet this incident highlights a systemic issue within open-source infrastructure like npm, which operates on limited resources and relies heavily on responsible use and community support. It underscores concerns that unchecked abuse, rather than malware, poses a significant threat to the sustainability and reliability of open-source ecosystems, as these platforms are often run by non-profits or small teams with limited funding and rely on the responsible use of shared resources by the community.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Vector Search | 1 | 1,668 | 286 | 111 | +15% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.