Scaling the Shadows: The "Flooding Dropper" Campaign and the Automated Weaponization of the npm Ecosystem

Executive Overview The open-source software supply chain is facing a relentless, highly structured assault. Threat researchers at Sonatype have issued an urgent warning to software developers and cybersecurity teams worldwide regarding an expanding, highly automated malware distribution campaign dubbed "Flooding Dropper." Tracked under the internal identifier sonatype-2026-005660, this malicious operation targets the Node Package Manager…

Read Full News

The Weaponization of Open Source: How North Korean State Hackers Infiltrate the Global Software Supply Chain

EXECUTIVE SUMMARY The global software development ecosystem is facing an unprecedented and intensifying security crisis, driven largely by state-sponsored threat actors weaponizing the very foundations of modern programming: open source software (OSS) libraries. A landmark security report published by Amazon has officially linked a coordinated series of high-profile open source supply chain compromises to a…

Read Full News