type: incident ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [incident, supply-chain, npm, rat, stealer, typo-squatting, sector-technology] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: true
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
OpenSourceMalware and Sonatype documented a campaign ('Flooding Dropper') of nearly 800 malicious npm packages using randomly generated typo-squatting names that deliver a cross-platform RAT/infostealer.
Key Details
- Source: The Hacker News
- Date: 2026-08-07
- Reliability: Tier 2/4 โ Established cyber journalism
- Nature: Malicious open-source supply-chain packages
Summary
- Packages use a downloader (WEL1DROPPER) that identifies the OS and architecture
- Fetches payloads from Cloudflare Workers hosts or DNS TXT records (wel1[.]ru)
- Libraries Windows ETW/AMSI patches and persistence
- Deploys Sliver on Linux
- Payload domains reference Russian financial institutions, suggesting targeted espionage against Russian fintech and mobile payments
Analysis
The campaign adds to a sustained period of open-source/supply-chain attacks (following the NullReceiver, Keyv npm-worm, and Open VSX malicious-extension disclosures). Australian developers and enterprises consuming npm packages should treat registry packages as an untrusted input surface.
Sources: raw/digests/Cyber-Digest-2026-08-08