• News/
  • https://www.bleepingcomputer.com/news/security/new-indonesianfoods-spammer-floods-npm-with-150-000-packages/

New ‘IndonesianFoods’ spammer floods npm with 150,000 packages

BleepingComputer
·
Published Nov 13, 2025
·
Updated

Article and title updated to remove the term "worm". See update below. An auto-spamming payload published on npm spams the registry by spawning new packages every seven seconds, creating large volumes of junk. The replicating payload, dubbed ‘IndonesianFoods,’ due to its distinctive package naming scheme that picks random Indonesian names and food terms, has published over 100,000 packages according to Sonatype, and the number is growing exponentially. Although the packages do not have a malicious component for developers (e.g., stealing data, backdooring hosts), this could change with an update that introduces a dangerous payload. The level of automation and large-scale nature of the attack create the potential for broad supply-chain compromise. Security researcher Paul McCarty, who first reported this spam campaign, created a page to track the offending npm publishers and the number of packages they have released on the platform. Sonatype reports that the same actors performed another attempt on September 10, with a package named ‘fajar-donat9-breki.’ Although that package contained the same replication logic, it failed to spread. “This attack has overwhelmed multiple security data systems, demonstrating unprecedented scale,” Sonatype’s principal security researcher, Garrett Calpouzos, told BleepingComputer. “Amazon Inspector is flagging these packages through OSV advisories, triggering a massive wave of vulnerability reports. Sonatype’s database alone saw 72,000 new advis...

Read full article

Affected Software

1 affected component
npm registry
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new spam attack on the npm registry by the 'IndonesianFoods' spammer that has flooded it with 150,000 packages.

2

What security implications are discussed?

The article highlights the risks of junk packages cluttering the npm registry, which can hinder legitimate development and pose security threats.

3

What products or software are affected?

The npm registry is the primary software affected by the spamming attack.

4

How frequently are new spam packages being published?

New spam packages are being published every seven seconds by the spamming payload.

5

What was the initial terminology used to describe the attack?

The article originally referred to the attack using the term "worm," which has since been removed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203