Threat reportSupply ChainTL-2026-1491

"Download Pumping" — npm Supply-Chain Trust-Signal Abuse via Mass Version Uploads (ambar-src / reverse_ssh / Apfell)

highACTIVE

"Download Pumping" (TL-2026-1491), also tracked as Download Pumping, is a high-severity supply-chain compromise, first published 2026-07-18. It has no confirmed attribution, affects npm, Inc. / npm public registry npm package registry, maps to 21 MITRE ATT&CK techniques (T1005, T1027, T1056), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
21MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-1491

Threat ID
TL-2026-1491
Also known as
Download Pumping, ambar-src campaign
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software-development, government administration, finance, health
Target regions
Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in "Download Pumping"

Malware and tooling: Apfell, reverse_ssh, MythicAgents / Mythic C2

How "Download Pumping" works

Tenable researcher Ron Popov documented 'download pumping', a supply-chain deception technique in which attackers publish hundreds of package versions in rapid succession so that registry mirrors, security scanners, and analysis bots auto-download each release, artificially inflating download counts and version-history depth to fake legitimacy. The technique was proven in the wild via the malicious npm package 'ambar-src' (a typosquat of 'ember-source'), which reached 724 versions (428 in its first two hours) and ~50,000 downloads in three days before npm removed it, then dropped platform-specific malware (Windows: encrypted-shellcode loader; Linux: reverse_ssh; macOS: Apfell/MythicAgents) via a hex-encoded preinstall script.

In mid-February 2026 Tenable Research identified a malicious npm package, 'ambar-src', that typosquatted the popular 'ember-source' package (11M+ downloads). The package was first uploaded on 2026-02-13 and published as a series of benign-looking versions — 428 of them in the first two hours alone, eventually reaching 724 total versions — before a weaponized version was pushed on 2026-02-16 at 12:18:45 UTC. npm removed the package roughly 4h44m later (17:02:44 UTC the same day), but by then it had accumulated approximately 50,000 downloads with zero legitimate human users.

The malicious version abused npm's `preinstall` lifecycle script hook defined in package.json: merely running `npm install ambar-src`, or having it resolve transitively as a dependency, was sufficient to trigger the payload with no explicit `require()`/import needed. The `index.js` preinstall script executed a hex-encoded, OS-specific one-liner to obscure intent, and the package interspersed legitimate-looking utility code (MathUtils, StringUtils, time helpers) with the malicious logic to evade cursory review.

Platform-specific second-stage payloads were fetched from the attacker-controlled domain x-ya[.]ru: on Windows, an encrypted-shellcode loader (msinit.exe, ~400KB) decoded and executed the shellcode in memory; on Linux, a bash script pulled an ELF binary ('osa') identified via Golang build metadata as a variant of the open-source reverse_ssh backdoor; on macOS, a nohup-wrapped hex command invoked the native `osascript` utility to run a ~500KB JavaScript payload identified as Apfell, part of the MythicAgents C2 framework family, capable of reconnaissance, screenshot capture, Google Chrome credential/session data theft, and fake password-prompt phishing overlays. Command-and-control communications were relayed through Yandex Cloud Functions (function.yandexcloud[.]ru / functions.yandexcloud.net), abusing a well-known cloud service to blend in with legitimate traffic (MITRE T1102 Web Service).

Separately, and more broadly, Tenable's Ron Popov demonstrated the underlying 'download pumping' abuse pattern with proof-of-concept test packages: every new version publish triggers automated downloads from registry mirrors and security-scanner/analysis-bot infrastructure — 135.55 downloads/version for a plain version bump, 141.91 for a static postinstall script, and 158.16 for a dynamically-changing postinstall script, implying scanners preferentially re-fetch versions that look newly suspicious. Because scanners can often determine whether a postinstall script exists purely from package metadata (without downloading the tarball), attackers can game detection infrastructure itself into serving as an amplification network. Tenable also revalidated a 2021-era technique of direct tarball-URL HTTP request flooding, inflating a test package to 17,000 downloads in about one hour — showing the older method still works alongside the newer one. ReversingLabs' write-up (crediting Popov) and Tenable's own technical FAQ both note the underlying registry infrastructure pattern is not npm-specific: PyPI, RubyGems, and NuGet operate comparable automated-mirror/scanner ecosystems and are described as similarly exposed.

The attack is notable for its convergence with AI-assisted coding tools, which frequently use download counts, version-history density, and maintenance-activity signals as heuristics for package trustworthiness/recommendation — none of which were designed as security controls and all of which download pumping can fabricate cheaply. Recommended mitigations center on enforcing minimum package-age windows (3-4+ days) before a newly published version is eligible for use in CI/CD or production, alongside version pinning, least-privilege network egress for build/CI environments, ephemeral just-in-time credentials in place of long-lived tokens, and stronger maintainer/publish authentication. Dissenting industry voices (James Shank, Expel; John Strand, BHIS) argued minimum-age gates only delay rather than prevent the attack, and that delaying legitimate updates may itself introduce operational risk that outweighs the benefit in many organizations.

MITRE ATT&CK techniques used in TL-2026-1491

Collection

T1005 Data from Local System; T1113 Screen Capture

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1620 Reflective Code Loading

Credential Access

T1056 Input Capture; T1555 Credentials from Password Stores

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer

Discovery

T1082 System Information Discovery

Initial Access

T1195 Supply Chain Compromise

Impact

T1491 Defacement

Persistence

T1505 Server Software Component; T1546 Event Triggered Execution

Resource Development

T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities

Affected products and versions in "Download Pumping"

  • npm, Inc. / npm public registry — npm package registry (registry.npmjs.org) and dependent automated infrastructure (mirrors, security scanners, analysis bots)
    Vulnerable versions: all versions of npm registry lifecycle-script/version-publish infrastructure as of 2026-02
  • npm ecosystem — ambar-src (malicious npm package, typosquat of ember-source)
    Vulnerable versions: 1 through 724 (malicious payload introduced in the version published 2026-02-16 12:18:45 UTC)
    Fixed in: removed from registry entirely 2026-02-16 17:02:44 UTC
  • Multiple package-registry operators — PyPI, RubyGems, NuGet (registries described by researchers as architecturally comparable/similarly exposed; no confirmed exploitation reported)
    Vulnerable versions: automated mirror/scanner infrastructure generally

Remediation for "Download Pumping"

Patches

  • No vendor patch applicable — 'ambar-src' was removed from the npm registry by npm within ~4h44m of the malicious version's publication (2026-02-16 12:18:45 UTC to 17:02:44 UTC)

Immediate actions

  • Treat any host that ran `npm install ambar-src` (or resolved it transitively) as fully compromised; do not attempt in-place cleanup
  • Rotate all secrets, API keys, tokens, and credentials stored on or accessible from an affected host, performed from a separate, known-clean machine
  • Block outbound connections to x-ya[.]ru, function.yandexcloud[.]ru, and the identified functions.yandexcloud.net URL paths
  • Search EDR/process telemetry for msinit.exe, the ELF binary 'osa', reverse_ssh process indicators, and osascript spawning unexpected child processes or network connections
  • Audit npm lockfiles and CI/CD dependency trees for 'ambar-src' or any package with an unexplained sudden spike (100s) of version publishes in a short window

Workarounds

  • Configure npm/yarn/pnpm to respect a package minimum-age threshold where supported before allowing install of newly published versions
  • Use internal registry proxies/mirrors with allowlisting so newly published packages require manual/automated security review before becoming installable org-wide

Longer-term hardening

  • Enforce a minimum package-age gate (3-4+ days) before a newly published registry version is permitted in CI/CD or production builds
  • Adopt version pinning / lockfile-only installs and disable automatic minor/patch version resolution in build pipelines
  • Replace long-lived npm/CI publish and consumption tokens with ephemeral, just-in-time scoped credentials
  • Apply least-privilege egress network policy to CI/CD runners and developer build environments to limit preinstall/postinstall script network access
  • Do not use raw download counts, version-history density, or publish-frequency as trust/legitimacy signals in internal tooling or AI-assisted package recommendation logic
  • Strengthen maintainer account authentication (mandatory 2FA/WebAuthn) on registry publish accounts

Weaknesses (CWE) in "Download Pumping"

CWE-506, CWE-1357, CWE-829

Timeline of "Download Pumping"

  • Independent researcher publicly demonstrates direct tarball-URL HTTP request flooding to spoof npm download counts, generating roughly 1 million spoofed downloads weekly — the precursor abuse pattern Tenable later revalidated
  • Cybernews, Security Boulevard, DevOps.com, and other outlets report on the ambar-src incident and its 50,000-download compromise
  • Tenable publishes its technical FAQ/analysis on the ambar-src malicious package, detailing platform-specific payloads, hashes, and C2 infrastructure
  • The 'ambar-src' package (typosquatting 'ember-source') is first published to the npm registry; 428 benign-looking versions are uploaded within the first two hours
  • By the time of removal and continuing to be tallied over the following days, ambar-src reaches 724 total published versions and approximately 50,000 downloads with zero legitimate users
  • npm removes ambar-src from the public registry at 17:02:44 UTC, roughly 4 hours 44 minutes after the malicious version's publication
  • A weaponized version of ambar-src is published at 12:18:45 UTC, containing a hex-encoded preinstall script that fetches OS-specific payloads from x-ya[.]ru
  • Tenable researcher Ron Popov publishes the broader 'download pumping' research, generalizing the ambar-src version-flooding pattern into a named technique and publishing proof-of-concept download-amplification measurements
  • ReversingLabs publishes 'Download pumping joins the trust-abuse bandwagon', crediting Tenable/Popov, summarizing the technique for a broader audience and noting industry pushback on minimum-age mitigations from James Shank (Expel) and John Strand (BHIS)

Sources cited for "Download Pumping"

Detection coverage for TL-2026-1491

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1491 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats