DevOps / SRE / Platform · 07.08.2026, 17:10 UTC
‘Flooding Dropper’ Is Hitting npm With a Tidal Wave of Malicious Packages
| Schweregrad | info |
|---|---|
| Kategorie | DevOps / SRE / Platform |
| Quelle | DevOps.com ↗ |
| Veröffentlicht | 07.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Threat researchers at Sonatype are warning developers of an expanding campaign that is generating a wide range of npm accounts and dropping small numbers of malicious packages from each one, essentially flooding the zone with a broadly distributed and automated campaign to make it difficult for defenders to keep up. So far, the campaign – dubbed “Flooding Dropper” – has affected almost 850 software components and comes with a package naming convention that initially contained terms such as “bigops” and “bnpl,” as seen in bigops-api and dolyame-boxy-desktop-bnpl-card-gallery. However, even that is evolving, with researchers seeing packages being created with other names. Overall, the nature of the campaign showcases growing trends of threat actors turning the publication of malicious packages into a more scalable operation and using open source malware in distributed and automated campaigns – rather than individual packages – to overwhelm registry moderation and blocklists. “Publishing malicious packages at scale is not new,” the researchers wrote in a report. “Distributing them across many disposable accounts makes containment harder. The Flooding Dropper threat actors are using account names that appear randomly generated, and individual accounts publish only a handful of packages. That prevents defenders from assuming that removing one prolific publisher will eliminate the broader operation.” More Pressure on npm For npm, it creates a moderation problem, they added, noting that “each account and package may need to be identified, reviewed, and removed independently while …