Scaling the Shadows: The "Flooding Dropper" Campaign and the Automated Weaponization of the npm Ecosystem
Executive Overview The open-source software supply chain is facing a relentless, highly structured assault. Threat researchers at Sonatype have issued an urgent warning to software developers and cybersecurity teams worldwide regarding an expanding, highly automated malware distribution campaign dubbed "Flooding Dropper." Tracked under the internal identifier sonatype-2026-005660, this malicious operation targets the Node Package Manager…
