A cluster of nearly 800 malicious npm packages is being used to deliver cross-platform malware that targets Windows, macOS, and Linux through a downloader called WEL1DROPPER and a staged payload delivery process. The campaign, tracked as Flooding Dropper and possibly linked to the earlier Moika operation, also overlaps with other npm and PyPI attacks that spread RATs, steal credentials, and abuse Chrome extensions for web crawling. #WEL1DROPPER #FloodingDropper #Moika #Sliver #InstaSkip
Keypoints
- Nearly 800 malicious npm packages were published in a new supply-chain campaign.
- The packages deliver WEL1DROPPER, a downloader that fetches platform-specific payloads.
- The attack targets Windows, macOS, and Linux with different delivery and persistence methods.
- Windows and macOS payloads attempt to evade monitoring, detect analysis tools, and set persistence.
- Linux samples can deploy Sliver through a Cloudflare Worker-based infrastructure.
Read More: https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html