WEL1DROPPER — 800 Malicious npm Packages RAT and Crypto Infostealer Campaign (August 2026)
Summary
WEL1DROPPER is a cross-platform malware downloader distributed through a large-scale npm supply-chain campaign, tracked by Sonatype as 'Flooding Dropper' (sonatype-2026-005660), which published between 788 and 1,033 confirmed malicious packages to the npm registry in August 2026. Upon execution via a developer's require() call, WEL1DROPPER fingerprints the host OS and fetches a platform-specific Remote Access Trojan and infostealer payload — with the Linux variant deploying the open-source Sliver C2 framework. Researchers at OpenSourceMalware assess the campaign as an evolution of the earlier Moika dependency-confusion operation, link C2 infrastructure to Aeza Group (a sanctioned Russian bulletproof host), and report a cryptocurrency drain routine capable of siphoning Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. A separate OX Security report from approximately the same period attributes a related but distinct npm RAT campaign to a North Korean-linked threat actor; the two campaigns share the npm supply-chain vector but have distinct infrastructure and attribution.
Connected Entities
1 entities · 10 linked investigationsTimeline(9 events)
2026-04-01
Moika dependency confusion campaign begins: over 250 malicious npm packages published, exfiltrating process.env contents and delivering OS-specific second-stage payloads. Assessed by OpenSourceMalware as a predecessor to WEL1DROPPER.
SafeDep Threat Intelligence / OpenSourceMalware2026-05-27
Moika Wave 1: npm accounts mr.4nd3r50n and pik-libs publish 164 malicious packages targeting cloud platform and financial services internal scopes within 25 minutes.
SafeDep2026-05-29
Moika Wave 2: Third account t-in-one adds 12 packages, including impersonation of Sberbank's payment widget. Microsoft Security Blog separately documents 33 malicious npm packages abusing dependency confusion.
SafeDep / Microsoft Security Blog2026-06-01
Moika Wave 3: Fourth account emcd-vue publishes packages impersonating EMCD cryptocurrency exchange with advanced obfuscation.
SafeDep2026-08-05
OpenSourceMalware researchers identify bigops-backend as the first documented WEL1DROPPER package, triggering a cross-platform native binary payload on Windows, Linux, and macOS.
The Hacker News / OpenSourceMalware2026-08-06
OpenSourceMalware publishes analysis of the AI slopsquatting campaign, documenting 700+ malicious npm packages published in approximately 48 hours and naming the campaign 'WEL1DROPPER'.
OpenSourceMalware2026-08-07
Sonatype Research Labs publishes campaign tracking under the name 'Flooding Dropper' (sonatype-2026-005660), identifying 846 malicious npm components. Campaign velocity reportedly slowed after discovery week.
Sonatype2026-08-08
SC Media and other outlets publish coverage. OpenSourceMalware co-founder Jenn Gile reports total confirmed WEL1DROPPER packages at 1,033.
SC Media / The Hacker News2026-08-10
The Hacker News publishes comprehensive coverage citing Sonatype and OpenSourceMalware research, describing 1,033 total packages, crypto drain capabilities, Aeza Group infrastructure link, and connection to Moika campaign.
The Hacker NewsDecision Log
- #1publish⛓ pending8/15/2026, 11:18:21 PMhash: GnPNA4MPmTJEbJh7jpjgNCNsRbNhArJ2fwL8ATNy4MHE
14 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/15/2026, 11:18:13 PM
last updated: 8/16/2026, 7:16:35 AM
avoid.net — verified advice for a post-truth world