Sonatype Research Labs reported an active software supply-chain campaign, dubbed Flooding Dropper, that pushed roughly 850 malicious npm packages through disposable publisher accounts and patterned package names and versions. The packages act as first-stage JavaScript loaders that fetch and execute platform-specific second-stage payloads for Windows, Linux, and macOS, using both HTTPS downloads and DNS TXT record fallback to maintain delivery if primary infrastructure is blocked.
The activity aligns with CWE-506: Embedded Malicious Code, a weakness category covering intentionally harmful functionality such as trojans, trapdoors, and spyware embedded in distributed software. Sonatype said the Windows payload uses defense evasion and persistence techniques including patching ETW and AMSI, checking for analysis environments, creating Registry Run keys and scheduled tasks, and reflectively loading an encrypted payload in memory; defenders are advised to treat any system that installed an affected package as compromised, investigate persistence and follow-on payload execution, and rotate exposed credentials only after remediation is complete.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
OpenSourceMalware reported the malicious npm package bigops-backend, which delivered a platform-specific binary to Windows, Linux, and macOS systems.
Researchers detailed the Flooding Dropper npm campaign as using hundreds of malicious packages that trick developers into executing them via README instructions, triggering the WEL1DROPPER downloader to fetch platform-specific malware. The disclosure described Cloudflare Workers and DNS TXT-based delivery, Windows ETW/AMSI tampering and persistence, macOS LaunchAgent persistence, and Linux deployment of Sliver.
MITRE published CWE-506, defining a software weakness in which a product contains code that appears malicious in nature, such as Trojan horses, trapdoors, logic bombs, or spyware.
Sonatype Research Labs assessed bigops-backend as part of a larger active npm supply-chain campaign it tracks as Flooding Dropper, with 846 implicated software components at the time of reporting.
MITRE's CWE Content Team updated the CWE-506 entry as part of CWE 4.15, reflecting maintenance of the weakness definition and related taxonomy content.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 44 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
8 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcetrojan-killer.net
Open sourcecyberveille.ch
Open sourcethehackernews.com
Open sourceopensourcemalware.com
Open sourcemalware.news
Open sourcesonatype.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.