Sign In

Supply Chain Attack Campaign

Ongoing

Flooding Dropper

Flooding Dropper is a large-scale malicious npm package cluster that uses numerous disposable publisher accounts and slightly mutated packages to distribute a common cross-platform malware loader. The packages execute during installation or import, select a Windows, Linux, or macOS payload, and retrieve it through rotating HTTPS hosts or a DNS TXT fallback. The loader writes the payload to a temporary location and launches it as a concealed, detached process, enabling subsequent malware stages to establish persistence, evade analysis, and execute additional encrypted payloads.

Ecosystems: npm

First discovered
2026-08-05
Last activity
2026-08-05
Affected Package Artifacts
865
(789 unique packages)
Package Artifacts Last 7 Days
0
0%
vs previous 7 days

Affected packages

Package
Published
Detected
Download CSV

Socket for GitHub

Socket Firewall

Socket CLI

Socket Certified Patches

Socket Web Extension

Socket Optimize

Socket Dependency Search

Socket Reachability

Languages

JavaScript / TypeScript

Stay in touch

Get open source security insights delivered straight into your inbox.

Book a DemoSign In

Made with ⚡️ by Socket Inc

U.S. Patent No. 12,346,443 & 12,314,394. Other pending.

SOC 2 Type II certified