Skip to main content
Sign in

WEL1DROPPER — 800 Malicious npm Packages RAT and Crypto Infostealer Campaign (August 2026)

avoid.net/wel1dropper-800-malicious-npm-packages-rat-and-crypto-infostealer-campaign-august-20260/100·85% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·stU75A…unsV

Summary

WEL1DROPPER is a cross-platform malware downloader distributed through a large-scale npm supply-chain campaign, tracked by Sonatype as 'Flooding Dropper' (sonatype-2026-005660), which published between 788 and 1,033 confirmed malicious packages to the npm registry in August 2026. Upon execution via a developer's require() call, WEL1DROPPER fingerprints the host OS and fetches a platform-specific Remote Access Trojan and infostealer payload — with the Linux variant deploying the open-source Sliver C2 framework. Researchers at OpenSourceMalware assess the campaign as an evolution of the earlier Moika dependency-confusion operation, link C2 infrastructure to Aeza Group (a sanctioned Russian bulletproof host), and report a cryptocurrency drain routine capable of siphoning Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. A separate OX Security report from approximately the same period attributes a related but distinct npm RAT campaign to a North Korean-linked threat actor; the two campaigns share the npm supply-chain vector but have distinct infrastructure and attribution.

Have evidence about WEL1DROPPER — 800 Malicious npm Packages RAT and Crypto Infostealer Campaign (August 2026)?

Timeline(9 events)

April 2026

Moika dependency confusion campaign begins: over 250 malicious npm packages published, exfiltrating process.env contents and delivering OS-specific second-stage payloads. Assessed by OpenSourceMalware as a predecessor to WEL1DROPPER.

SafeDep Threat Intelligence / OpenSourceMalware

27 May 2026

Moika Wave 1: npm accounts mr.4nd3r50n and pik-libs publish 164 malicious packages targeting cloud platform and financial services internal scopes within 25 minutes.

SafeDep

29 May 2026

Moika Wave 2: Third account t-in-one adds 12 packages, including impersonation of Sberbank's payment widget. Microsoft Security Blog separately documents 33 malicious npm packages abusing dependency confusion.

SafeDep / Microsoft Security Blog

June 2026

Moika Wave 3: Fourth account emcd-vue publishes packages impersonating EMCD cryptocurrency exchange with advanced obfuscation.

SafeDep

5 August 2026

OpenSourceMalware researchers identify bigops-backend as the first documented WEL1DROPPER package, triggering a cross-platform native binary payload on Windows, Linux, and macOS.

The Hacker News / OpenSourceMalware

6 August 2026

OpenSourceMalware publishes analysis of the AI slopsquatting campaign, documenting 700+ malicious npm packages published in approximately 48 hours and naming the campaign 'WEL1DROPPER'.

OpenSourceMalware

7 August 2026

Sonatype Research Labs publishes campaign tracking under the name 'Flooding Dropper' (sonatype-2026-005660), identifying 846 malicious npm components. Campaign velocity reportedly slowed after discovery week.

Sonatype

8 August 2026

SC Media and other outlets publish coverage. OpenSourceMalware co-founder Jenn Gile reports total confirmed WEL1DROPPER packages at 1,033.

SC Media / The Hacker News

10 August 2026

The Hacker News publishes comprehensive coverage citing Sonatype and OpenSourceMalware research, describing 1,033 total packages, crypto drain capabilities, Aeza Group infrastructure link, and connection to Moika campaign.

The Hacker News
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 15 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/15/2026, 11:18:13 PM

last updated: 8/25/2026, 7:47:48 PM

4 views

avoid.net — verified advice for a post-truth world