• News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
No Result
View All Result
Home AI

New Malicious npm Package Highlights the Speed at Which Supply Chain Risks Propagate – Tenable

SmartSolutionUser1 by SmartSolutionUser1
March 2, 2026
in AI
0
New Malicious npm Package Highlights the Speed at Which Supply Chain Risks Propagate – Tenable
76
SHARES
1.3k
VIEWS
Share on FacebookShare on Twitter

Tenable Research investigated a malicious package in the npm public registry named “amber-src” that underscores the rapid nature of modern supply chain attacks. The package, which was downloaded approximately 50,000 times before its removal, was designed to mimic a popular package “ember-source”, to infect developers’ systems across Windows, macOS, and Linux.

You might also like

5 Ways AI Is Transforming Business Travel – SAP Concur

LTM Launches BlueVerse for iRun to Outcreate Managed Services in the Agentic AI Era

Advised by Bestvantage Investments, TrackerSuite.AI Raises INR 6 Crore to Accelerate AI-Powered Business Operating System for SMEs Across India and Global Markets

The threat is unique because it does not require a developer to actually run any code to become a victim. The moment a user types the command to install the package, a hidden “preinstall script” executes automatically in the background. While the user sees a standard installation progress bar, the malware is already active, identifying the victim’s operating system and delivering the malware.

The attackers utilised a technique called “typosquatting,” naming the package “ambar-src” suspected to mimic a widely trusted package with over 11 million downloads. Unlike legitimate software that has been compromised, “ambar-src” was built from the ground up as a weapon, serving no functional purpose other than to deliver malware.

Mr. Ari Eitan, Director for Research at Tenable.
Mr. Ari Eitan, Director for Research at Tenable.

“The true danger of this package lies in how it weaponizes a simple human mistake,” said Mr. Ari Eitan, Director for Research at Tenable. “Developers often assume that if a package is available on a public registry, it is safe to download. By hiding the attack inside the installation process, hackers ensure they are inside your system before you’ve even had a chance to verify the code.”


The package was removed from the npm registry within five hours of the malicious version being published on February 16, 2026. However, any system where “ambar-src” is currently found should be considered fully compromised.

Tenable Research urges all organizations to audit their development environments and CI/CD pipelines for any presence of this package and follow standard incident response protocols if it is detected.

If you have an interesting Article / Report/case study to share, please get in touch with us at editors@roymediative.com  roy@roymediative.com, 9811346846/9625243429.

Tags: New Malicious npmPackage Highlights the Speedsmart solutions worldTenableWhich Supply Chain Risks Propagate
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

5 Ways AI Is Transforming Business Travel – SAP Concur

by SmartSolutionUser1
June 17, 2026
0
5 Ways AI Is Transforming Business Travel – SAP Concur

Business travel is entering a new era. For decades, corporate travel has largely been defined by processes: booking flights, securing approvals, staying within budgets and ensuring compliance with...

Read moreDetails

LTM Launches BlueVerse for iRun to Outcreate Managed Services in the Agentic AI Era

by SmartSolutionUser1
June 16, 2026
0
LTM Launches BlueVerse for iRun to Outcreate Managed Services in the Agentic AI Era

LTM, the Business Creativity partner to the world’s largest enterprises, announced the launch of BlueVerse™ for iRun, an AI-native managed services model designed to transform traditional IT operations...

Read moreDetails

Advised by Bestvantage Investments, TrackerSuite.AI Raises INR 6 Crore to Accelerate AI-Powered Business Operating System for SMEs Across India and Global Markets

by SmartSolutionUser1
June 16, 2026
0
Advised by Bestvantage Investments, TrackerSuite.AI Raises INR 6 Crore to Accelerate AI-Powered Business Operating System for SMEs Across India and Global Markets

TrackerSuite.AI,an AI-powered business automation platform helping small and medium enterprises (SMEs) digitise and streamline operations hassuccessfully raised INR 6 crore in a Pre Series A funding round led...

Read moreDetails

Sagility acquires CareSeed to accelerate AI-led quality operations and Medicare Advantage performance transformation

by SmartSolutionUser1
June 15, 2026
0
Sagility acquires CareSeed to accelerate AI-led quality operations and Medicare Advantage performance transformation

Sagility, a leading tech-enabled healthcare operations and transformation company, announced its acquisition of CareSeed, a U.S.-based healthcare analytics company specializing in NCQA-certified HEDIS quality reporting, medical record review,...

Read moreDetails

Shunya Labs Launches Multilingual Voice AI Platform Supporting 216+ Languages to Power Bharat’s Digital Inclusion

by SmartSolutionUser1
June 13, 2026
0
Shunya Labs Launches Multilingual Voice AI Platform Supporting 216+ Languages to Power Bharat’s Digital Inclusion

Shunya Labs, a pioneering AI innovation company focused on building custom language models and multilingual with Indic language speech recognition, announced the launch of its next-generation multilingual Voice...

Read moreDetails
Next Post
Iris Global delivers Dell Enterprise IT Infrastructure for FMCG Data Center Tech Refresh Through Mysuru Partner Raman IT

Iris Global delivers Dell Enterprise IT Infrastructure for FMCG Data Center Tech Refresh Through Mysuru Partner Raman IT

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

Browse by Category

Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

  • News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

BROWSE BY TAG

Acquisition Agentic AI Agora AI Akamai AMD Cloudflare CloudKeeper Coforge CrowdStrike Cybersecurity Databricks Fortinet Gartner GenAI Google Cloud HCLTech Honeywell IBM Infosys Kaspersky Keysight Kramer LTIMindtree Microsoft New Relic Nvidia OpenAI Palo Alto Networks PPDS Qlik Qualcomm Seqrite SiMa.ai smart solutions world smartsolutionsworld smart solutions world latest news Software Synology Tata Communications Tech Mahindra Technology Tenable UiPath Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

© 2024 NCN - Premium news & magazine by NCN.

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?