CyberSecurityBoardThreat Intel · CVEs · Products
Malware

WEL1DROPPER: Cross-Platform Downloader in npm Supply Chain Attack

August 7, 2026

WEL1DROPPER is a downloader used in a campaign involving nearly 800 malicious npm packages. It identifies the host OS and architecture, then fetches a compatible payload from Cloudflare Workers domains or via DNS TXT records from wel1[.]ru. It executes the final payload using /bin/sh or cmd.exe, and is associated with the 'Flooding Dropper' campaign tracked by Sonatype.