Get the latest tech news

70% of new NPM packages in last 6 months were spam


Headed to Black Hat USA? Come talk to us in Start-Up City at SC203! In April of this year, the Phylum Research Team revealed the proliferation of spam packages in npm associated with the Tea protocol, a decentralized initiative that promises to compensate software developers in cryptocurrency for their open-source

In April of this year, the Phylum Research Team revealed the proliferation of spam packages in npm associated with the Tea protocol, a decentralized initiative that promises to compensate software developers in cryptocurrency for their open-source contributions. Like the island of discarded plastic twice the size of Texas floating in the North Pacific Ocean, npm has accrued an astonishing amount of spam packages over the past six months. As the early SEO spammers figured out how to game PageRank for their benefit, history repeats itself, and a few software developers have spammed open-source repositories with absurd amounts of worthless packages.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of months

months

Photo of spam

spam

Photo of npm

npm

Related news:

News photo

Supermicro CEO teases service to build or upgrade datacenters in six months

News photo

Lenovo may have leaked a smaller Legion Go gaming handheld months ago

News photo

Thunderstorms Have Caused $45B in Damages in the U.S. in Six Months