Article and title updated to remove the term "worm". See update below. An auto-spamming payload published on npm spams the registry by spawning new packages every seven seconds, creating large volumes of junk. The replicating payload, dubbed ‘IndonesianFoods,’ due to its distinctive package naming scheme that picks random Indonesian names and food terms, has published over 100,000 packages according to Sonatype, and the number is growing exponentially. Although the packages do not have a malicious component for developers (e.g., stealing data, backdooring hosts), this could change with an update that introduces a dangerous payload. The level of automation and large-scale nature of the attack create the potential for broad supply-chain compromise. Security researcher Paul McCarty, who first reported this spam campaign, created a page to track the offending npm publishers and the number of packages they have released on the platform. Sonatype reports that the same actors performed another attempt on September 10, with a package named ‘fajar-donat9-breki.’ Although that package contained the same replication logic, it failed to spread. “This attack has overwhelmed multiple security data systems, demonstrating unprecedented scale,” Sonatype’s principal security researcher, Garrett Calpouzos, told BleepingComputer. “Amazon Inspector is flagging these packages through OSV advisories, triggering a massive wave of vulnerability reports. Sonatype’s database alone saw 72,000 new advis...
New ‘IndonesianFoods’ spammer floods npm with 150,000 packages
BleepingComputer
·Published Nov 13, 2025
·Updated
Affected Software
1 affected component
npm registry
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new spam attack on the npm registry by the 'IndonesianFoods' spammer that has flooded it with 150,000 packages.
2
What security implications are discussed?
The article highlights the risks of junk packages cluttering the npm registry, which can hinder legitimate development and pose security threats.
3
What products or software are affected?
The npm registry is the primary software affected by the spamming attack.
4
How frequently are new spam packages being published?
New spam packages are being published every seven seconds by the spamming payload.
5
What was the initial terminology used to describe the attack?
The article originally referred to the attack using the term "worm," which has since been removed.