PkgRadar

Tracked campaign · npm

Clob dropper

Three npm packages from publisher devcarron shipping identical postinstall droppers fetching a Windows PE via IPFS within a 4-minute burst.

2,334 packages attributednpm ecosystempkgradar source

First seen 2025-05-25

Attribution basis

These are the signal classes linking the members of this campaign — the broad evidence categories we use to attribute a package, not the raw indicators themselves.

Sample attributed packages

PkgRadar attributes coordinated supply-chain campaigns and blocks their packages at the CI gate. Start free or see all tracked campaigns.