logo

New Malicious npm Package "ambar-src" Targets Developers with Open Source Malware

ID: cb31000f-5e34-5f11-bd51-c9e60333a13f

STIX ID: report--cb31000f-5e34-5f11-bd51-c9e60333a13f

Feed Name: Tenable Blog

Threat Score
85/100

Date Published: 2026-02-24

Date Updated: 2026-05-01

Author: Ron Popov

...
...

Tenable Research analyzed a malicious npm package, "ambar-src", which used the npm preinstall hook and hex-encoded commands to fetch and execute OS-specific payloads (Windows msinit.exe, Linux reverse_ssh ELF, macOS Apfell), was downloaded roughly 50,000 times before removal, employed detection-evasion techniques, and includes a detailed IOC list (filenames, SHA256 hashes, domains, and Yandex Cloud function C2 URLs) along with recommended incident response actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.