CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Flooding Dropper: Sonatype’s Tracking Name for npm Malware Campaign

August 7, 2026

Flooding Dropper is the moniker used by Sonatype for the campaign involving nearly 800 malicious npm packages. The campaign delivers cross-platform malware with RAT and infostealer capabilities, using WEL1DROPPER as the initial downloader.