• News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
No Result
View All Result
Home AI

New Malicious npm Package Highlights the Speed at Which Supply Chain Risks Propagate – Tenable

SmartSolutionUser1 by SmartSolutionUser1
March 2, 2026
in AI
0
New Malicious npm Package Highlights the Speed at Which Supply Chain Risks Propagate – Tenable
76
SHARES
1.3k
VIEWS
Share on FacebookShare on Twitter

Tenable Research investigated a malicious package in the npm public registry named “amber-src” that underscores the rapid nature of modern supply chain attacks. The package, which was downloaded approximately 50,000 times before its removal, was designed to mimic a popular package “ember-source”, to infect developers’ systems across Windows, macOS, and Linux.

You might also like

HCLTech launches AI Innovation Zone in collaboration with Google Cloud

Nagarro partners with BrowserStack to ​​supercharge AI-powered testing workflows for enterprises

KushoAI Benchmark Finds AI Coding Tools Struggle With Complex API Bugs

The threat is unique because it does not require a developer to actually run any code to become a victim. The moment a user types the command to install the package, a hidden “preinstall script” executes automatically in the background. While the user sees a standard installation progress bar, the malware is already active, identifying the victim’s operating system and delivering the malware.

The attackers utilised a technique called “typosquatting,” naming the package “ambar-src” suspected to mimic a widely trusted package with over 11 million downloads. Unlike legitimate software that has been compromised, “ambar-src” was built from the ground up as a weapon, serving no functional purpose other than to deliver malware.

Mr. Ari Eitan, Director for Research at Tenable.
Mr. Ari Eitan, Director for Research at Tenable.

“The true danger of this package lies in how it weaponizes a simple human mistake,” said Mr. Ari Eitan, Director for Research at Tenable. “Developers often assume that if a package is available on a public registry, it is safe to download. By hiding the attack inside the installation process, hackers ensure they are inside your system before you’ve even had a chance to verify the code.”


The package was removed from the npm registry within five hours of the malicious version being published on February 16, 2026. However, any system where “ambar-src” is currently found should be considered fully compromised.

Tenable Research urges all organizations to audit their development environments and CI/CD pipelines for any presence of this package and follow standard incident response protocols if it is detected.

If you have an interesting Article / Report/case study to share, please get in touch with us at editors@roymediative.com  roy@roymediative.com, 9811346846/9625243429.

Tags: New Malicious npmPackage Highlights the Speedsmart solutions worldTenableWhich Supply Chain Risks Propagate
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

HCLTech launches AI Innovation Zone in collaboration with Google Cloud

by SmartSolutionUser1
June 10, 2026
0
HCLTech launches AI Innovation Zone in collaboration with Google Cloud

HCLTech, a leading global technology company, announced the launch of an AI Innovation Zone in collaboration with Google Cloud. Located in Santa Clara, California, the AI Innovation Zone...

Read moreDetails

Nagarro partners with BrowserStack to ​​supercharge AI-powered testing workflows for enterprises

by SmartSolutionUser1
June 10, 2026
0
Nagarro partners with BrowserStack to ​​supercharge AI-powered testing workflows for enterprises

Nagarro, a global AI transformation and engineering leader, has announced a strategic partnership with BrowserStack to co-develop test automation solutions for enterprises. The collaboration aims to integrate BrowserStack’s end-to-end, AI-powered...

Read moreDetails

KushoAI Benchmark Finds AI Coding Tools Struggle With Complex API Bugs

by SmartSolutionUser1
June 10, 2026
0
KushoAI Benchmark Finds AI Coding Tools Struggle With Complex API Bugs

KushoAI released the first comparative benchmark study of how leading AI coding and testing agents perform at finding bugs in live APIs. While AI tools generate plausible tests...

Read moreDetails

OptiValue Tek’s AI Patent Signals the Rise of Predictive Mobility Infrastructure

by SmartSolutionUser1
June 9, 2026
0
OptiValue Tek’s AI Patent Signals the Rise of Predictive Mobility Infrastructure

OptiValue Tek Consulting Ltd., a global digital engineering and AI-led technology consulting company, has announced the filing of a breakthrough patent focused on AI-powered driver intelligence, predictive safety...

Read moreDetails

Siemens powers the next phase of industrial AI with Intelligence Center X

by SmartSolutionUser1
June 9, 2026
0
Siemens powers the next phase of industrial AI with Intelligence Center X

Siemens announced Intelligence Center X, new industrial AI orchestration software designed to help organizations turn industrial AI from isolated experimentation into scalable, real world business impact through a...

Read moreDetails
Next Post
Iris Global delivers Dell Enterprise IT Infrastructure for FMCG Data Center Tech Refresh Through Mysuru Partner Raman IT

Iris Global delivers Dell Enterprise IT Infrastructure for FMCG Data Center Tech Refresh Through Mysuru Partner Raman IT

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

Browse by Category

Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

  • News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

BROWSE BY TAG

Acquisition Agentic AI Agora AI Akamai AMD Cloudflare CloudKeeper Coforge CrowdStrike Cybersecurity Databricks Fortinet Gartner GenAI Google Cloud HCLTech Honeywell IBM Infosys Kaspersky Keysight Kramer LTIMindtree Microsoft New Relic Nvidia OpenAI Palo Alto Networks PPDS Qlik Qualcomm Seqrite SiMa.ai smart solutions world smartsolutionsworld smart solutions world latest news Software Synology Tata Communications Tech Mahindra Technology Tenable UiPath Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • News In Brief
  • Influence Excellence Awards 2026
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

© 2024 NCN - Premium news & magazine by NCN.

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?