‘Flooding Dropper’ Is Hitting npm With a Tidal Wave of Malicious Packages August 7, 2026 by Jeff Burt Threat researchers at Sonatype are warning developers of an expanding campaign that is generating a wide range of npm accounts and dropping small numbers of malicious packages from each one, […]