WEL1DROPPER is a cross-platform downloader used in a large-scale npm supply-chain malware campaign targeting developer workstations and CI/CD environments. Malicious npm packages masquerade as benign libraries and trigger execution when imported, rather than relying solely on lifecycle scripts, allowing the malware to activate during normal package use. The first stage fingerprints the victim host by operating system and processor architecture, then retrieves a compatible native payload for Windows, macOS, or Linux. If primary HTTPS staging fails, it can reconstruct payloads from DNS TXT records, demonstrating resilient multi-channel delivery.
The malware is associated with a campaign tracked as Flooding Dropper and has been linked by researchers to tradecraft overlaps with the earlier Moika npm activity. The operation used hundreds of malicious npm packages, including typo-squatted, randomly generated, and AI-generated names, to increase the likelihood of accidental installation or use by developers.
On Windows, reported behavior includes sandbox and virtual-environment checks, interference with ETW and AMSI to reduce security visibility, detached execution of downloaded payloads, and persistence through autorun mechanisms and scheduled execution. On macOS, the malware performs anti-analysis checks for debugging and instrumentation artifacts, retrieves additional staged payloads, and establishes persistence via a LaunchAgent. On Linux, the delivered payload has been observed as a packed ELF executable, and researchers reported that the Linux branch can deploy Sliver. Across platforms, the campaign has been assessed as a developer-compromise operation that can expose credentials, tokens, source code, and other sensitive secrets from infected engineering systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
In Windows, the malware is reported to interfere with Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI), check for virtual environments and sandboxes, as well as establish persistence through Registry Run keys and scheduled processes.
Upon access to the compromised system, the malware retrieves multiple encoded chunks, combines them, decodes the resulting data, and executes the payload.
For Windows, the temporary dropper pattern reported by OpenSourceMalware is %TEMP%\dotnet_diag_<8 hex characters>.exe , started with cmd.exe /c start /b %TEMP%\dotnet_diag_<id>.exe .
In Windows, the malware is reported to interfere with Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI), check for virtual environments and sandboxes, as well as establish persistence through Registry Run keys and scheduled processes.
In Windows, the malware is reported to interfere with Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI), check for virtual environments and sandboxes, as well as establish persistence through Registry Run keys and scheduled processes.
This Linux version has been delivered as an ELF executable packed with UPX
The packages appear legitimate by using AI-generated, squatted, randomly generated, or typosquatted names.
Upon access to the compromised system, the malware retrieves multiple encoded chunks, combines them, decodes the resulting data, and executes the payload.
The package tries three Cloudflare Workers hosts first. If they fail, it switches to DNS TXT delivery and uses net.dl.wel1.ru for the Windows branch.
When the HTTPS delivery fails, it switches to DNS TXT records associated with the domain wel1[.]ru.
When the HTTPS delivery fails, it switches to DNS TXT records associated with the domain wel1[.]ru.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-platform downloader/dropper delivered via malicious npm packages. It fingerprints the victim OS and architecture, retrieves next-stage payloads over HTTPS or via DNS TXT fallback, reconstructs and executes encoded payload chunks, and includes evasion and persistence features such as ETW/AMSI interference on Windows, sandbox checks, Registry Run keys/scheduled tasks persistence on Windows, and LaunchAgent persistence on macOS.
A malicious npm-package campaign in which imported package code launches a cross-platform downloader/dropper. It identifies OS and CPU architecture, retrieves a native second-stage payload for Windows, macOS, or Linux, and can fall back to DNS TXT record delivery via wel1.ru when HTTPS delivery fails.
A cross-platform downloader used in malicious npm packages. It fingerprints the victim OS and architecture, retrieves staged payloads over HTTPS or via DNS TXT fallback, writes them to a temporary folder, and executes them. The Windows path includes ETW and AMSI patching, sandbox/VM checks, persistence via Registry Run key and scheduled task, and retrieval of an encrypted payload; macOS uses similar anti-analysis behavior and LaunchAgent persistence.
A cross-platform npm-delivered downloader/dropper campaign that executes on package import, retrieves native payloads over HTTPS from Cloudflare Workers or reconstructs them from DNS TXT records under wel1.ru, then silently executes them. The payload chain includes RAT/infostealer functionality, with the macOS stage adding anti-analysis, persistence via LaunchAgent, and retrieval of an additional beacon.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.