Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [incident, supply-chain, npm, rat, stealer, typo-squatting, sector-technology] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: true

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

OpenSourceMalware and Sonatype documented a campaign ('Flooding Dropper') of nearly 800 malicious npm packages using randomly generated typo-squatting names that deliver a cross-platform RAT/infostealer.

Key Details

  • Source: The Hacker News
  • Date: 2026-08-07
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Nature: Malicious open-source supply-chain packages

Summary

  • Packages use a downloader (WEL1DROPPER) that identifies the OS and architecture
  • Fetches payloads from Cloudflare Workers hosts or DNS TXT records (wel1[.]ru)
  • Libraries Windows ETW/AMSI patches and persistence
  • Deploys Sliver on Linux
  • Payload domains reference Russian financial institutions, suggesting targeted espionage against Russian fintech and mobile payments

Analysis

The campaign adds to a sustained period of open-source/supply-chain attacks (following the NullReceiver, Keyv npm-worm, and Open VSX malicious-extension disclosures). Australian developers and enterprises consuming npm packages should treat registry packages as an untrusted input surface.

Sources: raw/digests/Cyber-Digest-2026-08-08