A large-scale attack is flooding the npm open source registry with thousands of fake packages. The goal? To steal tokens from developers using the Tea Protocol, a blockchain-based reward system for open source work. This campaign has grown rapidly, with researchers at Amazon estimating over 150,000 infected packages. Sonatype, a software supply chain company, confirms










