Amazon finds 150K npm packages linked to token-farming campaign

November 17, 2025

Attackers used automation to publish malicious packages that earned cryptocurrency rewards without user awareness.