• Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions
No Result
View All Result
No Result
View All Result
Home AI

New Malicious npm Package Highlights the Speed at Which Supply Chain Risks Propagate – Tenable

SmartSolutionUser1 by SmartSolutionUser1
March 2, 2026
in AI
0
New Malicious npm Package Highlights the Speed at Which Supply Chain Risks Propagate – Tenable
76
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Tenable Research investigated a malicious package in the npm public registry named “amber-src” that underscores the rapid nature of modern supply chain attacks. The package, which was downloaded approximately 50,000 times before its removal, was designed to mimic a popular package “ember-source”, to infect developers’ systems across Windows, macOS, and Linux.

You might also like

2026 Smart City Summit & Expo – AI Creates New Urban Horizons

New Relic Introduces Platform Innovations to Connect Technical Performance with Business Outcomes

Honeywell Process Technology to Support Verso Energy in Advancing eSAF Production

The threat is unique because it does not require a developer to actually run any code to become a victim. The moment a user types the command to install the package, a hidden “preinstall script” executes automatically in the background. While the user sees a standard installation progress bar, the malware is already active, identifying the victim’s operating system and delivering the malware.

The attackers utilised a technique called “typosquatting,” naming the package “ambar-src” suspected to mimic a widely trusted package with over 11 million downloads. Unlike legitimate software that has been compromised, “ambar-src” was built from the ground up as a weapon, serving no functional purpose other than to deliver malware.

Mr. Ari Eitan, Director for Research at Tenable.
Mr. Ari Eitan, Director for Research at Tenable.

“The true danger of this package lies in how it weaponizes a simple human mistake,” said Mr. Ari Eitan, Director for Research at Tenable. “Developers often assume that if a package is available on a public registry, it is safe to download. By hiding the attack inside the installation process, hackers ensure they are inside your system before you’ve even had a chance to verify the code.”


The package was removed from the npm registry within five hours of the malicious version being published on February 16, 2026. However, any system where “ambar-src” is currently found should be considered fully compromised.

Tenable Research urges all organizations to audit their development environments and CI/CD pipelines for any presence of this package and follow standard incident response protocols if it is detected.

If you have an interesting Article / Report/case study to share, please get in touch with us at editors@roymediative.com  roy@roymediative.com, 9811346846/9625243429.

Tags: New Malicious npmPackage Highlights the Speedsmart solutions worldTenableWhich Supply Chain Risks Propagate
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

2026 Smart City Summit & Expo – AI Creates New Urban Horizons

by SmartSolutionUser1
March 9, 2026
0
2026 Smart City Summit & Expo – AI Creates New Urban Horizons

Taiwan is putting cities in control of their own AI brains. The 13th Smart City Summit & Expo (SCSE) and Net Zero City Exhibition opens March 17 at...

Read moreDetails

New Relic Introduces Platform Innovations to Connect Technical Performance with Business Outcomes

by SmartSolutionUser1
March 9, 2026
0
New Relic Introduces Platform Innovations to Connect Technical Performance with Business Outcomes

New Relic, the Intelligent Observability company, announced a series of platform innovations that connect technical performance to customer impact and business outcomes. Led by Intelligent Workloads that automate...

Read moreDetails

Honeywell Process Technology to Support Verso Energy in Advancing eSAF Production

by SmartSolutionUser1
March 9, 2026
0
Honeywell Process Technology to Support Verso Energy in Advancing eSAF Production

Honeywell announced that Verso Energy, an integrated energy company focused on producing low-carbon molecules, will use Honeywell UOP’s eFiningTM methanol-to-jet processing technology to produce electro-sustainable aviation fuel (eSAF)...

Read moreDetails

Splunk Report – Agentic AI Takes Centre Stage in CISOs’ Path to Digital Resilience

by SmartSolutionUser1
March 9, 2026
0
Splunk Report – Agentic AI Takes Centre Stage in CISOs’ Path to Digital Resilience

Cisco announced the release of Splunk’s annual report, The CISO Report: From Risk to Resilience in the AI Era, surveying 650 global Chief Information Security Officers (CISOs). The...

Read moreDetails

Airtel Payments Bank Launches Instant NFC-Based Balance Update for its RuPay On-The-Go Cards

by SmartSolutionUser1
March 9, 2026
0
Airtel Payments Bank Launches Instant NFC-Based Balance Update for its RuPay On-The-Go Cards

Airtel Payments Bank announced the launch of its Instant NFC-Based Balance Update feature for its RuPay On-The-Go Cards, enabled with NCMC. Customers can now instantly check or update...

Read moreDetails
Next Post
Iris Global delivers Dell Enterprise IT Infrastructure for FMCG Data Center Tech Refresh Through Mysuru Partner Raman IT

Iris Global delivers Dell Enterprise IT Infrastructure for FMCG Data Center Tech Refresh Through Mysuru Partner Raman IT

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

4 AI startups building solutions for India’s unique healthcare challenges

4 AI startups building solutions for India’s unique healthcare challenges

December 15, 2025
Kaspersky Partners With Technobind

Veeam and Microsoft to improve data resilience with AI

March 5, 2025
Esri India and TERI SAS Ink Pact to Advance Geospatial Education and Research

Esri India and TERI SAS Ink Pact to Advance Geospatial Education and Research

January 17, 2026

Browse by Category

  • Agora
  • AI
  • Article
  • AV Solutions
  • Business
  • Careers
  • Case Study
  • Cover Story
  • cyber security
  • EDU Solutions
  • Featured Article
  • Finance
  • Gartner
  • Global Academic
  • Health
  • Indian Government
  • Innovation
  • Interview
  • Interview
  • IT industry,
  • Jobs
  • Market
  • Networking
  • Nucleus Software
  • Open Ai
  • Politics
  • Products
  • Products Plus
  • projects
  • Security
  • SentinelOne®
  • Software
  • Solutions
  • Solutions Launch world
  • Solutions News World | Latest Tech & Innovation Updates
  • Startups
  • tech mahindra
  • Technology
  • Terafac Technologies
  • Uncategorized
Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

CATEGORIES

  • Agora
  • AI
  • Article
  • AV Solutions
  • Business
  • Careers
  • Case Study
  • Cover Story
  • cyber security
  • EDU Solutions
  • Featured Article
  • Finance
  • Gartner
  • Global Academic
  • Health
  • Indian Government
  • Innovation
  • Interview
  • Interview
  • IT industry,
  • Jobs
  • Market
  • Networking
  • Nucleus Software
  • Open Ai
  • Politics
  • Products
  • Products Plus
  • projects
  • Security
  • SentinelOne®
  • Software
  • Solutions
  • Solutions Launch world
  • Solutions News World | Latest Tech & Innovation Updates
  • Startups
  • tech mahindra
  • Technology
  • Terafac Technologies
  • Uncategorized

BROWSE BY TAG

Acquisition Agentic AI Agora AI Akamai AMD automation Cloudflare CloudKeeper CrowdStrike CyberArk Cybersecurity Databricks Fortinet Gartner GenAI Google Cloud Honeywell IBM India AI Impact Summit 2026 Infosys Kaspersky Kramer LTIMindtree Microsoft New Relic NTT DATA Nvidia OpenAI Palo Alto Networks PPDS Qlik Qualcomm ServiceNow smart solutions world smartsolutionsworld smart solutions world latest news Snowflake Software Sophos Tata Communications Tech Mahindra Technology Tenable Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions

© 2024 NCN - Premium news & magazine by NCN.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?