Cybersecurity

Over 46,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack

November 13, 2025 1 min read SkillMX Editorial Desk
Article Data

Cybersecurity researchers are calling attention to a large-scale spam campaign that has flooded the npm registry with thousands of fake packages since early 2024. "The packages were systematically published over an extended period," Endor Labs says.

Read more on The Hacker News

Loading next article