Supply Chain Attack Campaign
Flooding Dropper is a large-scale malicious npm package cluster that uses numerous disposable publisher accounts and slightly mutated packages to distribute a common cross-platform malware loader. The packages execute during installation or import, select a Windows, Linux, or macOS payload, and retrieve it through rotating HTTPS hosts or a DNS TXT fallback. The loader writes the payload to a temporary location and launches it as a concealed, detached process, enabling subsequent malware stages to establish persistence, evade analysis, and execute additional encrypted payloads.
Ecosystems: npm