THREAT OPS › Threat News › Flooding Dropper Hits npm With 850 Malicious Packages
Flooding Dropper Hits npm With 850 Malicious Packages
<div class="hs-featured-image-wrapper"> <a class="hs-featured-image-link" href="https://www.sonatype.com/blog/flooding-dropper-hits-npm-with-850-malicious-packages" title=""> <img alt="Image with text "Breaking news: Sonatype Research indentified sonatype-2026-005660, new 'flooding dropper' campaign "" class="hs-featured-image" src="https://www.sonatype.com/hubfs/RapidResponse_Flooding
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
- JavaScriptT1059.007
- CredentialsT1589.001
- Malicious PackageAML.T0011.001
Indicators of compromise
- https://guide.sonatype.com/vulnerability/sonatype-2026-005660/sonatype-researchurl
- https://opensourcemalware.com/npm/bigops-backendurl
- track.hubspot.comdomain
- 2fwww.sonatype.comdomain
- 252fwww.sonatype.comdomain