Skip to main content
← Back to Demos
SBOM intermediate · 15 min

SBOM Analysis Flags Vulnerable npm Dependencies in the WEL1DROPPER Wave

On August 8, 2026, researcher Paul McCarty (OpenSourceMalware) detailed a new npm supply-chain campaign: nearly 800 malicious packages using "AI slop" and randomly generated typosquat names. Unlike lifecycle-hook attacks, the packages instruct developers to load them with require(), executing a downloader named WEL1DROPPER that profiles the host OS and CPU architecture and fetches a compatible RAT or infostealer payload from three Cloudflare Workers hosts — spanning Windows, macOS and Linux. The same blind spot that let those packages slip into registries and CI pipelines lives in every dependency tree: pinned packages with known, patchable vulnerabilities. This demo ships a synthetic application manifest whose dependency list pins lodash 4.17.20 (CVE-2021-23337, command injection), minimist 1.2.5 (CVE-2021-44906, prototype pollution) and async 2.6.3 (CVE-2021-43138, prototype pollution) — alongside benign metadata; nothing real is downloaded. MetaDefender SBOM generates a software bill of materials, cross-references every dependency against vulnerability and threat intelligence, pinpoints the poisoned packages and their versions, and reports the exposure path, so security teams can block a release before a compromised component ships.

Attack Technique

Malicious package in dependency tree (T1195.002)

MITRE ATT&CK

T1195.002 ↗

Platforms

linux

File Types

.docx

MetaDefender Capabilities

SBOM

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---