New Malicious npm Package "ambar-src" Targets Developers with Open Source Malware
ID: cb31000f-5e34-5f11-bd51-c9e60333a13f
STIX ID: report--cb31000f-5e34-5f11-bd51-c9e60333a13f
Feed Name: Tenable Blog
Threat Score
Tenable Research analyzed a malicious npm package, "ambar-src", which used the npm preinstall hook and hex-encoded commands to fetch and execute OS-specific payloads (Windows msinit.exe, Linux reverse_ssh ELF, macOS Apfell), was downloaded roughly 50,000 times before removal, employed detection-evasion techniques, and includes a detailed IOC list (filenames, SHA256 hashes, domains, and Yandex Cloud function C2 URLs) along with recommended incident response actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
