A self-spreading package published on npm spams the registry by spawning new packages every seven seconds, creating large volumes of junk. The worm, dubbed ‘IndonesianFoods,’ due to its distinctive package naming scheme that picks random Indonesian names and food terms, has published over 100,000 packages according to Sonatype, and the number is growing exponentially. Although the packages do not have a malicious component for developers (e.g., stealing data, backdooring hosts), this could change with an update that introduces a dangerous payload. The level of automation and large-scale nature of the attack create the potential for broad supply-chain compromise. Security researcher Paul McCarty, who first reported this spam campaign, created a page to track the offending npm publishers and the number of packages they have released on the platform. Sonatype reports that the same actors performed another attempt on September 10, with a package named ‘fajar-donat9-breki.’ Although that package contained the same replication logic, it failed to spread. “This attack has overwhelmed multiple security data systems, demonstrating unprecedented scale,” Sonatype’s principal security researcher, Garrett Calpouzos, told BleepingComputer. “Amazon Inspector is flagging these packages through OSV advisories, triggering a massive wave of vulnerability reports. Sonatype’s database alone saw 72,000 new advisories in a single day.” The researcher commented that IndonesianFoods does not appear ...
New ‘IndonesianFoods’ worm floods npm with 100,000 packages
BleepingComputer
·Bill Toulas
·Published Nov 13, 2025
·Updated
Affected Software
1 affected component
npm package
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the 'IndonesianFoods' worm that is flooding the npm registry with a large number of spam packages.
2
What security implications are discussed?
The article highlights how the 'IndonesianFoods' worm can disrupt the npm ecosystem by overwhelming it with junk packages.
3
What products or software are affected?
The affected software in this incident is the npm package registry, which is inundated with spam packages.
4
How often does the worm spawn new packages?
The 'IndonesianFoods' worm spawns new packages every seven seconds.
5
What is the significance of the naming scheme for the packages?
The naming scheme of the packages is distinctive and random, which is a characteristic feature of the 'IndonesianFoods' worm.