logo

The 50,000-Download Trap: How ‘ambar-src’ Typosquatting Compromised Windows, Linux, and macOS Devs

ID: 9680993b-0bf4-587a-8bff-b2e82cde38a6

STIX ID: report--9680993b-0bf4-587a-8bff-b2e82cde38a6

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-02-27

Date Updated: 2026-04-23

Author: Ddos

...
...

Tenable Research discovered a malicious npm package, "ambar-src," that used typosquatting against the popular "ember-source" package to distribute cross-platform malware via npm's preinstall hook; the package amassed ~50,000 downloads before removal and delivers Windows (msinit.exe with encrypted shellcode), Linux (ELF 'osa' reverse SSH client), and macOS (Apfell) payloads, using legitimate cloud services for C2 and recommending that any affected systems be treated as fully compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.