Sonatype Identifies 846-Package npm Campaign Using Automated Account Creation to Evade Deny Lists

The campaign, tracked as Flooding Dropper, generates accounts and package names through automated interpolation of legitimate package strings — names like variations of "bigops" and "bnpl" — then publishes slightly modified versions across multiple accounts. The variation is sufficient to frustrate simple deny lists while the underlying payload delivery remains consistent.

When a targeted package is installed, it downloads and executes a secondary payload through multiple delivery methods, improving the campaign's success rate against different environment configurations. The use of multiple delivery paths suggests the attackers are optimising against detection at the download layer as well as the execution layer.

The economic logic is what makes the Flooding Dropper approach notable. Publishing malicious packages at scale is not a new tactic, but coordinating 846 packages with sufficient variation to survive blocklist filtering while keeping the payload consistent requires a degree of automation that lowers the cost of entry for subsequent campaigns. Organisations depending on npm for development pipelines should treat the pattern as a sign that manual package auditing is insufficient at scale.

Sonatype's advisory advises affected organisations to act immediately to prevent malicious dependencies from compromising development environments. The full technical breakdown is available on the Sonatype blog.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News