Listen to this Post

The npm ecosystem, a cornerstone of modern software development, is facing an unprecedented wave of automated spam. A self-replicating package campaign, dubbed IndonesianFoods, is flooding the registry with thousands of new packages every few seconds. While the packages currently lack direct malicious payloads targeting developers, their scale and speed have raised alarms about potential supply-chain risks and ecosystem instability.
Summary of the IndonesianFoods Campaign
A new package-spamming worm, IndonesianFoods, has been detected on npm, the world’s largest JavaScript package repository. The worm automatically generates and publishes new packages every seven seconds, naming them after random combinations of Indonesian names and foods. Security researchers from Sonatype estimate over 100,000 packages have already been published, and the number continues to grow exponentially.
Interestingly, these packages do not currently contain harmful code designed to steal data or compromise developer machines. However, researchers warn that future updates could introduce malicious payloads. The automation and large-scale nature of the campaign could create significant supply-chain vulnerabilities if exploited.
Security researcher Paul McCarty, who first reported the campaign, has created a tracking page for the offending publishers. A follow-up attack on September 10, involving the package fajar-donat9-breki, replicated the same behavior but failed to spread further. Garret Calpouzos, principal security researcher at Sonatype, notes that the attack has overwhelmed multiple security monitoring systems, triggering massive waves of vulnerability advisories. For instance, Sonatype recorded 72,000 new advisories in a single day, highlighting the sheer scale of this campaign.
Although IndonesianFoods appears primarily designed to stress-test and disrupt the ecosystem rather than infiltrate developer machines, the motivation remains partially unclear. Some packages appear to abuse the TEA Protocol, a blockchain-based system rewarding open-source contributions with TEA tokens. By publishing interconnected packages, attackers inflated their impact scores to earn tokens, indicating a financial incentive.
The campaign dates back to 2023, with 43,000 packages added, TEA monetization in 2024, and the replication loop introduced in 2025. This mirrors a broader trend of automated attacks on open-source ecosystems, including the GlassWorm attack on OpenVSX, Shai-Hulud dependency-confusion propagation, and hijacking of popular npm packages like chalk and debug. Individually, these incidents caused limited damage, but collectively they reveal a growing threat from automation-driven supply-chain attacks.
Developers are advised to take precautionary measures: lock down dependency versions, monitor abnormal publishing patterns, and implement strict digital signature validation policies to mitigate potential risks.
What Undercode Say: Analyzing the IndonesianFoods Impact
The IndonesianFoods worm represents a significant evolution in automated attacks on open-source ecosystems. Its strategy is simple yet devastating: exploit automation to create high-volume, low-complexity disruptions. By generating over 100,000 packages, attackers create a flood of noise that overwhelms security monitoring systems and makes detection of malicious packages more difficult.
From a supply-chain perspective, this is particularly concerning. Open-source ecosystems operate on trust; developers assume that published packages are benign unless flagged otherwise. When a worm like IndonesianFoods introduces hundreds of thousands of semi-legitimate packages, it erodes trust in the registry itself. Future updates could embed malicious payloads that propagate automatically, creating a cascading effect across projects worldwide.
Financial incentives, via mechanisms like the TEA Protocol, add a layer of complexity. The campaign shows that attackers are not only motivated by disruption but also by tokenized reward systems. This highlights a new hybrid threat model: attacks that combine financial gain, automation, and ecosystem stress testing.
Furthermore, the IndonesianFoods campaign illustrates a shift from traditional attacks targeting individual machines to macro-scale attacks targeting the ecosystem itself. While previous incidents like GlassWorm or Shai-Hulud exploited dependencies, they were relatively contained. IndonesianFoods, by contrast, is essentially a digital spam flood, testing the limits of registry infrastructure and incident response systems.
For cybersecurity teams and open-source maintainers, this is a wake-up call. Traditional vulnerability scanning may be insufficient when faced with high-volume, automated replication. Organizations need proactive monitoring, anomaly detection, and stricter publishing standards. Automated tooling should be able to flag unusual publishing rates, odd naming patterns, and abnormal token-inflation activities.
Strategically, the campaign may also influence policy discussions in the open-source community. How do registries balance openness and security? How can reward systems like TEA Protocols be safeguarded against exploitation? These questions point to a long-term governance challenge for npm and similar ecosystems.
In the bigger picture, IndonesianFoods is symptomatic of the broader trend: attackers exploiting automation, scale, and gamification of open-source contributions. It’s a hybrid of social engineering, financial incentive abuse, and operational disruption, all rolled into a single automated campaign. Ecosystem resilience will increasingly depend on visibility, transparency, and robust automated defenses, ensuring that the flood of packages does not translate into a flood of vulnerabilities.
Fact Checker Results
✅ The campaign has published over 100,000 npm packages.
✅ IndonesianFoods packages currently lack harmful payloads for developers.
❌ The worm does not yet compromise developer machines directly.
Prediction
📊 As automation in open-source grows, attacks like IndonesianFoods will likely become more sophisticated. We may see future campaigns integrating real malicious payloads, automated propagation across multiple ecosystems, and exploitation of token-based reward systems. The npm registry and similar platforms will need stricter publishing controls, anomaly detection algorithms, and cross-platform monitoring to mitigate these emerging threats. Early adoption of dependency lockdown policies and automated security audits will be critical in preventing large-scale ecosystem compromise.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




