Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Amazon reported that its researchers identified more than 150,000 npm packages tied to a coordinated tea.xyz token-farming campaign. The packages automatically generated and published more packages, apparently to inflate activity metrics used to earn cryptocurrency rewards. “Worm-powered” describes that self-replication—not evidence that the packages stole credentials or carried destructive payloads.

What Amazon found

In a report published November 13, 2025, AWS said Amazon Inspector researchers uncovered more than 150,000 npm packages associated with a campaign targeting tea.xyz, a blockchain-based system designed to reward open-source developers. AWS characterized the activity as a self-replicating attack pattern: automated package creation and publication without legitimate functionality, intended to collect cryptocurrency rewards without users’ awareness. AWS’s campaign report provides the campaign-specific count and chronology.

The figure is specific to the tea.xyz campaign in that 2025 report. A separate, later Amazon Inspector research summary—updated May 13, 2026—lists lifetime detection totals of 188,538 npm packages and 12 PyPI packages across its program. Those dynamic totals cover more than this campaign and should not be read as a revised tea.xyz count. Amazon Inspector’s research documentation describes the broader program.

How the worm-like publishing worked

AWS’s account emphasizes automated replication, package generation, and publication. SecurityWeek’s November 14, 2025 technical account describes a routine that created additional packages, changed their metadata to make them public, and published them to npm. It also reports that a tea.yaml file connected packages to blockchain wallet addresses and was likely intended to improve their visibility or ranking within the reward system. This technical description is secondary reporting; AWS is the source for the campaign count and discovery timeline. SecurityWeek’s account gives further detail on the reported routine.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The practical meaning of “worm” here is propagation through creation and publication of more packages. The available accounts do not establish that the packages stole secrets, installed backdoors, or destroyed data. SecurityWeek distinguishes them from packages containing overtly malicious code of that traditional kind. That does not make the campaign harmless: flooding a public registry and manipulating a reward system can undermine package discovery, while downloading and executing untrusted code carries downstream risk.

Why the packages are still a security concern

A package can be abusive even if it does not behave like a credential stealer or destructive malware. The campaign’s reported purpose was to produce nonfunctional or low-quality packages and inflate metrics for financial reward. A large volume of such entries pollutes a registry that developers rely on to find useful software. Separately, any package that a team chooses to install and execute becomes part of its software supply chain, so teams should not treat unfamiliar dependencies as safe solely because a particular campaign was not reported to use a conventional theft payload.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

This campaign should not be conflated with the separately discussed Shai-Hulud npm worm or later credential-stealing incidents. The reviewed accounts do not say the tea.xyz package flood used the same payload or objectives. They also do not establish a particular country or person behind the campaign, or the ultimate value of any tokens collected.

How Amazon detected and handled the campaign

  1. October 24, 2025: Amazon Inspector researchers deployed a new detection rule paired with AI to identify additional suspicious npm package patterns.
  2. By November 7: The system had flagged thousands of packages for investigation.
  3. November 8: Researchers contacted the OpenSSF to coordinate. After validating and analyzing the pattern, they systematically submitted packages to the OpenSSF Malicious Packages Repository.
  4. Through November 12: The operation continued, ultimately uncovering more than 150,000 packages. AWS published its report the following day.

AWS says the rule and AI helped identify patterns; its account also describes validation and coordination. The finding should not be understood as an AI model independently confirming every package. Amazon Inspector’s broader documented process combines automated detection pipelines with expert analyst review. For confirmed malicious packages, the program assigns a MAL-ID, publishes an advisory, contributes intelligence to the OpenSSF repository, and can integrate findings into Amazon Inspector for customers whose workloads consume an affected package. These capabilities do not mean every advisory generates a finding in every customer environment. The Inspector documentation describes the program and supported registries, including npm and PyPI.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What development teams can take from the incident

  • Use malicious-package detection and software supply-chain controls to identify suspicious dependencies; evaluate whether a tool covers the registries and package inventories your team actually uses.
  • Review package identity, provenance, maintainers, and behavior before adding unfamiliar dependencies, especially when a package has little useful functionality or appears as part of an unusual cluster.
  • Treat public advisories as threat intelligence to investigate against your own dependency inventory. A registry advisory alone does not prove that your environment installed or executed the package.

Amazon Inspector is one documented example: AWS says it monitors supported public package registries, combines automated detection with analyst review, and can surface relevant findings to customers. The available material does not provide a basis for ranking it against other providers.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.