Another Day, Another Shady Bash

The Influx of Packages
This isn’t a fresh episode of Geordie Shore, but the npm registry has been struck again, mate. This time with an influx of 150K packages, causing quite the hassle for developers worldwide. No ransomware involved, just a crafty token farming scheme.
Not Your Typical Culprits
You might assume they’d opt for ransomware, eh? Nope, this time the clever chaps behind this scheme chose to dive headfirst into a token farming operation. Smart, but not as shrewd as my Jack Russell when he’s filched my gym socks.
Amazon Lets the Cat Out of the Bag
Amazon has weighed in, stating this is “one of the largest package flooding events in open source registry history.” Indeed, and it’s hardly shocking, considering the enormous scale of this madness. Another day, another ridiculous trick to keep an eye on in the tech scene.
Amazon Revealed the Details
Once more, a supply chain breach has struck the npm registry in what Amazon labels “one of the largest package flooding events in open source registry history” – but with a twist. Rather than inserting credential-stealing code or ransomware into the packages, this one is a token farming initiative.…

