TL;DRSonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. On August 5, 2026, security researchers from OpenSourceMalware reported a malicious npm package named bigops-backend that delivered a platform-specific binary to Windows, Linux, and macOS systems. Rather than relying on a single publisher, the campaign generates npm accounts and publishes small numbers of packages from each one. Inside the ‘Flooding Dropper’ Campaign on npmThe malicious packages contain code that runs when the package is installed or imported. Once executed, it:Checks environment variables and local state (Read more...)*** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Sonatype Security Research Team.