U.S. Report Warns of China Telecom Risks as npm Attack Floods 846 Malicious Packages
This digest was compiled by AI from multiple sources — links to the originals are below.

Attackers released 846 malicious npm packages in a coordinated campaign that abuses automated account creation to distribute second-stage payloads, researchers at Sonatype reported. The packages, disguised with names like 'bigops' and 'bnpl', use varied delivery methods and syntactic changes to evade detection. The campaign unfolded as a U.S. congressional committee warned that Chinese telecom firms’ residual access to U.S. infrastructure could enable future cyber operations.
npm Supply Chain Attack
Researchers at Sonatype identified a large-scale malicious npm campaign, dubbed 'Flooding Dropper,' comprising 846 packages. The attacker automated the creation of npm accounts and packages, combining terms like 'bigops' and 'bnpl' with recurring version patterns in the 35.x.y range. Upon installation, each package downloads a second-stage payload using multiple delivery methods, and minor syntactic differences between packages help them evade signature-based detection.
U.S. Congressional Warning on Chinese Telecoms
The U.S. House Select Committee on China released a 49-page report titled 'Stranger Pings' detailing the threat of China-controlled telecommunications infrastructure. The report notes that Chinese telecom firms operating in the U.S. retain trusted positions that could be exploited by state-backed actors, such as those behind the Salt Typhoon campaign. One provider’s contract terms prohibited U.S. partners from broadcasting 'political news against state laws of the PRC' or content violating 'social order and social stability.'
SideWinder’s ClickOnce Phishing
The SideWinder threat actor group deployed a multi-stage attack using ClickOnce application files delivered through phishing PDF documents. The malicious files install Rust-based backdoors that establish persistence by modifying the Windows registry and collect host intelligence. The backdoors communicate with remote command servers hosted on free platforms like Cloudflare Workers.
What's Next
The npm registry maintainers are expected to review and remove the identified packages, but the automated creation technique could resurface in new variants. Analysts caution that Chinese telecom providers’ enduring access may complicate efforts to harden U.S. networks against state-directed cyber intrusions.
1 source
U.S. Report Warns of China Telecom Risks as npm Attack Floods 846 Malicious Packages






