• News/
  • https://www.bleepingcomputer.com/news/security/new-indonesianfoods-worm-floods-npm-with-100-000-packages/

New ‘IndonesianFoods’ worm floods npm with 100,000 packages

BleepingComputer
·
Bill Toulas
·
Published Nov 13, 2025
·
Updated

A self-spreading package published on npm spams the registry by spawning new packages every seven seconds, creating large volumes of junk. The worm, dubbed ‘IndonesianFoods,’ due to its distinctive package naming scheme that picks random Indonesian names and food terms, has published over 100,000 packages according to Sonatype, and the number is growing exponentially. Although the packages do not have a malicious component for developers (e.g., stealing data, backdooring hosts), this could change with an update that introduces a dangerous payload. The level of automation and large-scale nature of the attack create the potential for broad supply-chain compromise. Security researcher Paul McCarty, who first reported this spam campaign, created a page to track the offending npm publishers and the number of packages they have released on the platform. Sonatype reports that the same actors performed another attempt on September 10, with a package named ‘fajar-donat9-breki.’ Although that package contained the same replication logic, it failed to spread. “This attack has overwhelmed multiple security data systems, demonstrating unprecedented scale,” Sonatype’s principal security researcher, Garrett Calpouzos, told BleepingComputer. “Amazon Inspector is flagging these packages through OSV advisories, triggering a massive wave of vulnerability reports. Sonatype’s database alone saw 72,000 new advisories in a single day.” The researcher commented that IndonesianFoods does not appear ...

Read full article

Affected Software

1 affected component
npm package
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the 'IndonesianFoods' worm that is flooding the npm registry with a large number of spam packages.

2

What security implications are discussed?

The article highlights how the 'IndonesianFoods' worm can disrupt the npm ecosystem by overwhelming it with junk packages.

3

What products or software are affected?

The affected software in this incident is the npm package registry, which is inundated with spam packages.

4

How often does the worm spawn new packages?

The 'IndonesianFoods' worm spawns new packages every seven seconds.

5

What is the significance of the naming scheme for the packages?

The naming scheme of the packages is distinctive and random, which is a characteristic feature of the 'IndonesianFoods' worm.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203