Automated Package Registry Abuse

discovered 2026-05-27

Mass-publishing packages to npm via automated shell scripts (auto-publish.sh) to rapidly deploy adware infrastructure across many package names.

Seen in packages