Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

The Great Indonesian TEA Theft: Analyzing a NPM Spam Campaign

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Cris Staicu
Word Count
1,909
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

Security researcher Paul McCarty uncovered a large-scale spam campaign in the npm ecosystem, dubbed the IndonesianFoods worm, involving over 43,000 spam packages with dormant payloads, published over two years. The worm's distinctive naming scheme, using Indonesian names and food terms, points to its origin. Despite no immediate malicious code, the campaign's complexity lies in its ability to remain undetected by current security measures, as the packages appear legitimate and only become active when specific scripts are manually executed. The attack exploits the TEA protocol to monetize through TEA token rewards by artificially inflating impact scores via circular dependencies, highlighting significant gaps in npm's security framework. The campaign's success over a prolonged period, facilitated by at least eleven coordinated accounts, underscores vulnerabilities in the npm ecosystem, emphasizing the need for improved detection systems and proactive measures to maintain trust and prevent similar future attacks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.