Skip to main content
AVOID.NET

Fact-check findings

What an automated fact-checker found when it re-read WEL1DROPPER — 800 Malicious npm Packages RAT and Crypto Infostealer Campaign (August 2026) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed 7partially supported 2confirmed 327 corrections pending · 0 applied

disputed

7 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #7[disputed][awaiting moderator]in the summary
    “A separate OX Security report from approximately the same period attributes a related but distinct npm RAT campaign to a North Korean-linked threat actor”
    reviewerA separate OX Security report from approximately the same period attributes a related but distinct npm RAT campaign to a North Korean-linked threat actorThe OX Security 'terminal-logger-utils' report predates the WEL1DROPPER campaign by about three months; describing it as contemporaneous is inaccurate.
    Proposed correction (not yet applied)
    A separate OX Security report published in May 2026, roughly three months before the WEL1DROPPER campaign, attributes a related but distinct npm RAT campaign to a North Korean-linked threat actor
  2. #31[disputed][awaiting moderator]in section: Separate North Korean npm Campaign (OX Security Report)
    “Concurrent with the WEL1DROPPER/Flooding Dropper campaign, OX Security published a separate report attributing a distinct npm RAT campaign to a North Korean-linked threat actor.”
    reviewerConcurrent with the WEL1DROPPER/Flooding Dropper campaign, OX Security published a separate report on a distinct North Korean-linked npm RAT campaignSame underlying timing error as the summary-level claim; the report is not concurrent with WEL1DROPPER.
    Proposed correction (not yet applied)
    Published in May 2026, roughly three months before the WEL1DROPPER/Flooding Dropper campaign, OX Security published a separate report attributing a distinct npm RAT campaign to a North Korean-linked threat actor.
  3. #32[disputed][awaiting moderator]in section: Separate North Korean npm Campaign (OX Security Report)
    “https://www.securityweek.com/north-korean-hackers-blamed-for-mastra-npm-supply-chain-attack/”
    reviewerThe SecurityWeek article cited alongside OX Security's report describes the same North Korean npm RAT campaign (terminal-logger-utils / FAMOUS CHOLLIMA)This citation supports a genuine but unrelated North Korean npm supply-chain incident (Mastra/easy-day-js/Sapphire Sleet), not the terminal-logger-utils/FAMOUS CHOLLIMA campaign the section describes. As cited here it does not support the claims in this section.
  4. #33[disputed][awaiting moderator]in the cited sources
    “https://www.securityweek.com/north-korean-hackers-blamed-for-mastra-npm-supply-chain-attack/”
    reviewerThe SecurityWeek Mastra article is listed among sources_used to support this page's North Korean npm campaign narrativeSame underlying defect as the in-section citation of this URL.
  5. #35[disputed][awaiting moderator]in the timeline
    “2026-04”
    reviewerMoika dependency confusion campaign began in April 2026, publishing over 250 malicious npm packagesThree independent primary/secondary sources place the campaign's actual start in late May 2026, not April 2026. This appears to conflate loose phrasing elsewhere ('published in April/May') with an actual April start date.
    Proposed correction (not yet applied)
    2026-05
  6. #36[disputed][awaiting moderator]in the timeline
    “2026-04-01”
    reviewerMoika campaign's original/discovery date is 2026-04-01Same underlying date error as timeline[0].date.
    Proposed correction (not yet applied)
    2026-05-27
  7. #37[disputed][awaiting moderator]in the timeline
    “2026-08-07”
    reviewerSonatype Research Labs published its 'Flooding Dropper' tracking post on August 7, 2026Two independent fetches of the Sonatype post and its syndicated mirror both give a publication dateline of August 5, 2026, two days earlier than the page's stated date.
    Proposed correction (not yet applied)
    2026-08-05

partially supported

2 claims

The cited evidence supports part of the claim but not all of it.

  1. #6[partially supported][awaiting moderator]in the summary
    “report a cryptocurrency drain routine capable of siphoning Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP”
    reviewerThe malware includes a crypto-drain routine able to siphon Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRPThe claim is corroborated by a secondary aggregator (Cyber Recaps) attributing it to Sonatype, but the primary Sonatype blog post as directly fetched does not itself contain this detail. The page's own text already flags this exact gap ('attributed to secondary reporting... medium confidence'), so the hedge is appropriate; verdict reflects that the underlying sourcing chain is not fully closed.
  2. #19[partially supported][awaiting moderator]in section: Windows and macOS Payload Capabilities
    “The malware reportedly includes a 'DRAIN' routine that checks cryptocurrency wallet balances and can siphon funds — including calculated amounts as small as 1% — or the entirety of balances, for Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP.”
    reviewerThe crypto drain routine can siphon calculated amounts as small as 1% or entire balancesSame underlying sourcing gap as the summary-level drain claim; the page already appropriately discloses this in its own text.

confirmed

32 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    “WEL1DROPPER is a cross-platform malware downloader distributed through a large-scale npm supply-chain campaign, tracked by Sonatype as 'Flooding Dropper' (sonatype-2026-005660)”
    reviewerWEL1DROPPER is a cross-platform malware downloader distributed via a large-scale npm supply-chain campaign, tracked by Sonatype as 'Flooding Dropper' (sonatype-2026-005660)Both the campaign name pairing and tracking ID are directly confirmed by the primary Sonatype post and corroborating news coverage.
  2. #2[confirmed][no action needed]in the summary
    “which published between 788 and 1,033 confirmed malicious packages to the npm registry in August 2026”
    reviewerBetween 788 and 1,033 confirmed malicious packages were published in August 2026The stated range accurately reflects genuinely differing tallies reported by different outlets/researchers over the campaign's life (788 SC Media, 846 Sonatype, 1,033 Gile/Hacker News).
  3. #3[confirmed][no action needed]in the summary
    “Upon execution via a developer's require() call, WEL1DROPPER fingerprints the host OS and fetches a platform-specific Remote Access Trojan and infostealer payload — with the Linux variant deploying the open-source Sliver C2 framework.”
    reviewerUpon require(), WEL1DROPPER fingerprints the host OS and fetches a platform-specific RAT/infostealer, with the Linux variant deploying Sliver C2Confirmed across multiple independent sources.
  4. #4[confirmed][no action needed]in the summary
    “Researchers at OpenSourceMalware assess the campaign as an evolution of the earlier Moika dependency-confusion operation”
    reviewerOpenSourceMalware assesses the campaign as an evolution of the earlier Moika dependency-confusion operationConfirmed, and appropriately hedged elsewhere on the page as medium-confidence assessment.
  5. #5[confirmed][no action needed]in the summary
    “link C2 infrastructure to Aeza Group (a sanctioned Russian bulletproof host)”
    reviewerC2 infrastructure is linked to Aeza Group, a sanctioned Russian bulletproof hostIndependently corroborated that WEL1DROPPER infrastructure was linked to Aeza Group by researchers.
  6. #8[confirmed][no action needed]in section: Campaign Overview
    “In August 2026, security researchers at OpenSourceMalware first identified a malicious npm package named 'bigops-backend' on August 5, 2026, that delivered platform-specific binaries to Windows, Linux, and macOS systems.”
    reviewerOpenSourceMalware first identified the malicious npm package 'bigops-backend' on August 5, 2026Confirmed by multiple sources including Sonatype's own account.
  7. #9[confirmed][no action needed]in section: Campaign Overview
    “identifying 846 malicious npm components as of their initial publication”
    reviewerSonatype identified 846 malicious npm components as of their initial publicationExact figure confirmed by the primary source and a syndicated mirror (Security Boulevard).
  8. #10[confirmed][no action needed]in section: Campaign Overview
    “OpenSourceMalware co-founder Jenn Gile reported to The Hacker News that the total number of confirmed packages reached 1,033.”
    reviewerOpenSourceMalware co-founder Jenn Gile reported to The Hacker News that the total number of confirmed packages reached 1,033Confirmed.
  9. #11[confirmed][no action needed]in section: Campaign Overview
    “Rather than relying on npm lifecycle hooks (preinstall, postinstall) — a technique commonly monitored by security tooling — the packages included README files instructing developers to load them via a direct require() call, bypassing conventional detection.”
    reviewerThe packages bypassed lifecycle hooks by instructing developers via README to load them with a direct require() callStrongly corroborated by multiple independent write-ups of the OpenSourceMalware research.
  10. #12[confirmed][no action needed]in section: Campaign Overview
    “The campaign used disposable npm accounts publishing only a handful of packages each to prevent removal of any single publisher from eliminating the operation.”
    reviewerDisposable npm accounts published only a handful of packages eachConfirmed.
  11. #13[confirmed][no action needed]in section: Campaign Overview
    “Package names frequently interpolate business or SDK-themed terms such as 'bigops' and 'bnpl', with many packages sharing version numbers in the 35.x.y range”
    reviewerPackage names interpolate terms like 'bigops'/'bnpl' with version numbers frequently in the 35.x.y range, and OpenSourceMalware terms this 'AI slopsquatting'Confirmed, and the term 'AI slopsquatting' is confirmed as OpenSourceMalware's own coinage.
  12. #14[confirmed][no action needed]in section: Technical Mechanism: WEL1DROPPER Payload Delivery
    “If HTTPS delivery from Cloudflare Workers hosts fails, WEL1DROPPER falls back to a covert DNS channel: it queries DNS TXT records on platform-specific subdomains of wel1[.]ru (e.g., net.dl.wel1.ru, sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru), parses the returned value as a chunk count (accepting values between 1 and 2,000), requests numbered TXT records, joins the returned strings, and Base64-decodes the result into a binary buffer.”
    reviewerWEL1DROPPER uses dual-channel delivery: Cloudflare Workers HTTPS hosts, falling back to DNS TXT records on wel1[.]ru subdomains with chunked Base64-encoded payloadsThe specific subdomains and dual-channel mechanism are confirmed across primary and secondary sources.
  13. #15[confirmed][no action needed]in section: Technical Mechanism: WEL1DROPPER Payload Delivery
    “Windows — update_win.exe fetched from /pkg/update_win.exe, dropped temporarily to %TEMP%\dotnet_diag_<8 hex characters>.exe”
    reviewerWindows dropper is temporarily placed at %TEMP%\dotnet_diag_<8 hex characters>.exeConfirmed via search-indexed content since direct fetch of the primary IOC source was blocked (403 Forbidden).
  14. #16[confirmed][no action needed]in section: Technical Mechanism: WEL1DROPPER Payload Delivery
    “macOS — beacon_mac.bin with a similar anti-analysis framework; Linux — an UPX-packed ELF binary leading to the open-source Sliver C2 framework with section headers removed.”
    reviewermacOS payload is beacon_mac.bin with similar anti-analysis framework; Linux payload is a UPX-packed ELF with section headers removed leading to SliverConfirmed.
  15. #17[confirmed][no action needed]in section: Windows and macOS Payload Capabilities
    “It patches Event Tracing for Windows (ETW) functions and interferes with the Antimalware Scan Interface (AMSI) to suppress security monitoring. It checks for the presence of debuggers, virtual machines, sandboxes, and security products, and aborts execution if these are detected.”
    reviewerWindows payload patches ETW, interferes with AMSI, and checks for debuggers/VMs/sandboxes before establishing persistence via Registry Run key and scheduled taskConfirmed.
  16. #18[confirmed][no action needed]in section: Windows and macOS Payload Capabilities
    “The macOS payload, beacon_mac.bin, implements similar anti-analysis detection and establishes persistence via a LaunchAgent mechanism.”
    reviewermacOS variant establishes persistence via a LaunchAgent mechanismConfirmed.
  17. #20[confirmed][no action needed]in section: Linux Variant: Sliver C2 Framework
    “ARM64 architecture support was also reported, indicating that the campaign targets not only traditional x86-64 Linux servers but also ARM-based developer environments.”
    reviewerSliver is an open-source C2 framework originally built for legitimate red-team use, increasingly adopted by threat actors; ARM64 support was also reportedConfirmed.
  18. #21[confirmed][no action needed]in section: Attribution: Russian Threat Actor Assessment
    “The primary C2 fallback domain, wel1[.]ru, is a Russian country-code TLD domain, and the presence of domains such as tcsbank[.]ru (associated with Tinkoff Credit Systems Bank) and cloudpayments[.]ru in the macOS payload suggests potential targeting of Russian financial institutions and mobile payment systems.”
    reviewerwel1[.]ru is a Russian ccTLD domain, with tcsbank[.]ru and cloudpayments[.]ru strings found in the macOS payloadConfirmed.
  19. #22[confirmed][no action needed]in section: Attribution: Russian Threat Actor Assessment
    “The C2 infrastructure has been linked by researchers to Aeza Group, a Russian bulletproof hosting provider sanctioned by the U.S. government for supporting ransomware gangs and infostealer operations including BianLian ransomware and infostealers such as RedLine, Lumma, and Meduza.”
    reviewerAeza Group is a sanctioned Russian bulletproof hosting provider linked to BianLian ransomware and infostealers RedLine, Lumma, and MeduzaExact match to the source's wording — a precise, well-supported claim.
  20. #23[confirmed][no action needed]in section: Attribution: Russian Threat Actor Assessment
    “This attribution is assessed with medium confidence; it is based on infrastructure and tradecraft overlap identified by private security researchers rather than any government finding, indictment, or admitted attribution.”
    reviewerOpenSourceMalware links WEL1DROPPER to Moika via shared 'oob'-named infrastructure, telemetry camouflage, kill-switch mechanisms; assessed at medium confidence with no government attributionThe hedge is accurate — no government/law-enforcement attribution has been found for this campaign.
  21. #24[confirmed][no action needed]in section: Relationship to Moika Dependency Confusion Campaign
    “Wave 1 (May 27, 2026) involved two npm accounts publishing 164 malicious packages impersonating internal scopes of a cloud platform and financial services organization within 25 minutes.”
    reviewerMoika Wave 1 (May 27, 2026): two npm accounts published 164 malicious packages within 25 minutesConfirmed, exact figures match.
  22. #25[confirmed][no action needed]in section: Relationship to Moika Dependency Confusion Campaign
    “Wave 2 (May 29) added 12 packages targeting additional scopes including Sberbank's payment widget.”
    reviewerMoika Wave 2 (May 29) added 12 packages targeting Sberbank's payment widgetConfirmed.
  23. #26[confirmed][no action needed]in section: Relationship to Moika Dependency Confusion Campaign
    “Wave 3 (June 1) added further packages impersonating EMCD, a cryptocurrency exchange.”
    reviewerMoika Wave 3 (June 1) added packages impersonating EMCD cryptocurrency exchangeConfirmed.
  24. #27[confirmed][no action needed]in section: Relationship to Moika Dependency Confusion Campaign
    “All waves shared a single hardcoded C2 endpoint (https://oob.moika.tech/report) and a shared authentication secret, proving unified attribution across accounts.”
    reviewerAll Moika waves shared a single hardcoded C2 endpoint (https://oob.moika.tech/report) and a shared authentication secretConfirmed.
  25. #28[confirmed][no action needed]in section: Relationship to Moika Dependency Confusion Campaign
    “The Moika campaign exfiltrated raw process.env contents — potentially including cloud credentials, API tokens, and deployment secrets — to the attacker's server.”
    reviewerThe Moika campaign exfiltrated raw process.env contentsConfirmed.
  26. #29[confirmed][no action needed]in section: Relationship to Moika Dependency Confusion Campaign
    “Microsoft also documented related dependency confusion activity in a May 29, 2026 blog post identifying 33 malicious npm packages abusing the same technique.”
    reviewerMicrosoft documented related dependency confusion activity in a May 29, 2026 blog post identifying 33 malicious npm packagesConfirmed; matches the same underlying campaign as SafeDep's report.
  27. #30[confirmed][no action needed]in section: Separate North Korean npm Campaign (OX Security Report)
    “That campaign centered on a package named 'terminal-logger-utils' (published by npm account 'jpeek895'), which delivered keylogger, infostealer, and RAT functionality targeting Telegram data, SSH keys, cryptocurrency wallets, cloud configurations (AWS, GCP, Azure), and environment variables. Three dependent packages imported it: pretty-logger-utils, ts-logger-pack, and pinno-loggers.”
    reviewerOX Security's report centers on 'terminal-logger-utils' (published by 'jpeek895'), with dependent packages pretty-logger-utils, ts-logger-pack, and pinno-loggers, attributed to FAMOUS CHOLLIMA/Contagious Interview via OX Security and kmsec.ukConfirmed by direct fetch of the OX Security post.
  28. #34[confirmed][no action needed]in section: Separate North Korean npm Campaign (OX Security Report)
    “This North Korean campaign is a distinct operation from WEL1DROPPER and uses different infrastructure, delivery methods (postinstall hooks), and C2 architecture.”
    reviewerThe North Korean campaign is a distinct operation from WEL1DROPPER using different infrastructure, delivery methods, and C2 architectureThis distinction itself is accurate, independent of the timing issue flagged separately.
  29. #38[confirmed][no action needed]in the timeline
    “OpenSourceMalware publishes analysis of the AI slopsquatting campaign, documenting 700+ malicious npm packages published in approximately 48 hours and naming the campaign 'WEL1DROPPER'.”
    reviewerOpenSourceMalware published its WEL1DROPPER/'AI slopsquatting' analysis on August 6, 2026, documenting 700+ packages published in ~48 hoursDate and figures both confirmed precisely.
  30. #39[confirmed][no action needed]in the timeline
    “OpenSourceMalware researchers identify bigops-backend as the first documented WEL1DROPPER package, triggering a cross-platform native binary payload on Windows, Linux, and macOS.”
    reviewerOpenSourceMalware researchers identified bigops-backend as the first documented WEL1DROPPER package on 2026-08-05Confirmed.
  31. #40[confirmed][no action needed]in the timeline
    “SC Media and other outlets publish coverage. OpenSourceMalware co-founder Jenn Gile reports total confirmed WEL1DROPPER packages at 1,033.”
    reviewerSC Media and other outlets published coverage on August 8, 2026, with Jenn Gile reporting a total of 1,033 confirmed packagesConfirmed.
  32. #41[confirmed][no action needed]in the timeline
    “The Hacker News publishes comprehensive coverage citing Sonatype and OpenSourceMalware research, describing 1,033 total packages, crypto drain capabilities, Aeza Group infrastructure link, and connection to Moika campaign.”
    reviewerThe Hacker News published comprehensive coverage on August 10, 2026 citing Sonatype and OpenSourceMalware, describing 1,033 total packages, crypto drain, Aeza Group link, and Moika connectionConfirmed.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.