Threat reportSupply ChainTL-2026-1491
"Download Pumping" — npm Supply-Chain Trust-Signal Abuse via Mass Version Uploads (ambar-src / reverse_ssh / Apfell)
"Download Pumping" (TL-2026-1491), also tracked as Download Pumping, is a high-severity supply-chain compromise, first published 2026-07-18. It has no confirmed attribution, affects npm, Inc. / npm public registry npm package registry, maps to 21 MITRE ATT&CK techniques (T1005, T1027, T1056), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-1491
- Threat ID
- TL-2026-1491
- Also known as
- Download Pumping, ambar-src campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, government administration, finance, health
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in "Download Pumping"
Malware and tooling: Apfell, reverse_ssh, MythicAgents / Mythic C2
How "Download Pumping" works
Tenable researcher Ron Popov documented 'download pumping', a supply-chain deception technique in which attackers publish hundreds of package versions in rapid succession so that registry mirrors, security scanners, and analysis bots auto-download each release, artificially inflating download counts and version-history depth to fake legitimacy. The technique was proven in the wild via the malicious npm package 'ambar-src' (a typosquat of 'ember-source'), which reached 724 versions (428 in its first two hours) and ~50,000 downloads in three days before npm removed it, then dropped platform-specific malware (Windows: encrypted-shellcode loader; Linux: reverse_ssh; macOS: Apfell/MythicAgents) via a hex-encoded preinstall script.
In mid-February 2026 Tenable Research identified a malicious npm package, 'ambar-src', that typosquatted the popular 'ember-source' package (11M+ downloads). The package was first uploaded on 2026-02-13 and published as a series of benign-looking versions — 428 of them in the first two hours alone, eventually reaching 724 total versions — before a weaponized version was pushed on 2026-02-16 at 12:18:45 UTC. npm removed the package roughly 4h44m later (17:02:44 UTC the same day), but by then it had accumulated approximately 50,000 downloads with zero legitimate human users.
The malicious version abused npm's `preinstall` lifecycle script hook defined in package.json: merely running `npm install ambar-src`, or having it resolve transitively as a dependency, was sufficient to trigger the payload with no explicit `require()`/import needed. The `index.js` preinstall script executed a hex-encoded, OS-specific one-liner to obscure intent, and the package interspersed legitimate-looking utility code (MathUtils, StringUtils, time helpers) with the malicious logic to evade cursory review.
Platform-specific second-stage payloads were fetched from the attacker-controlled domain x-ya[.]ru: on Windows, an encrypted-shellcode loader (msinit.exe, ~400KB) decoded and executed the shellcode in memory; on Linux, a bash script pulled an ELF binary ('osa') identified via Golang build metadata as a variant of the open-source reverse_ssh backdoor; on macOS, a nohup-wrapped hex command invoked the native `osascript` utility to run a ~500KB JavaScript payload identified as Apfell, part of the MythicAgents C2 framework family, capable of reconnaissance, screenshot capture, Google Chrome credential/session data theft, and fake password-prompt phishing overlays. Command-and-control communications were relayed through Yandex Cloud Functions (function.yandexcloud[.]ru / functions.yandexcloud.net), abusing a well-known cloud service to blend in with legitimate traffic (MITRE T1102 Web Service).
Separately, and more broadly, Tenable's Ron Popov demonstrated the underlying 'download pumping' abuse pattern with proof-of-concept test packages: every new version publish triggers automated downloads from registry mirrors and security-scanner/analysis-bot infrastructure — 135.55 downloads/version for a plain version bump, 141.91 for a static postinstall script, and 158.16 for a dynamically-changing postinstall script, implying scanners preferentially re-fetch versions that look newly suspicious. Because scanners can often determine whether a postinstall script exists purely from package metadata (without downloading the tarball), attackers can game detection infrastructure itself into serving as an amplification network. Tenable also revalidated a 2021-era technique of direct tarball-URL HTTP request flooding, inflating a test package to 17,000 downloads in about one hour — showing the older method still works alongside the newer one. ReversingLabs' write-up (crediting Popov) and Tenable's own technical FAQ both note the underlying registry infrastructure pattern is not npm-specific: PyPI, RubyGems, and NuGet operate comparable automated-mirror/scanner ecosystems and are described as similarly exposed.
The attack is notable for its convergence with AI-assisted coding tools, which frequently use download counts, version-history density, and maintenance-activity signals as heuristics for package trustworthiness/recommendation — none of which were designed as security controls and all of which download pumping can fabricate cheaply. Recommended mitigations center on enforcing minimum package-age windows (3-4+ days) before a newly published version is eligible for use in CI/CD or production, alongside version pinning, least-privilege network egress for build/CI environments, ephemeral just-in-time credentials in place of long-lived tokens, and stronger maintainer/publish authentication. Dissenting industry voices (James Shank, Expel; John Strand, BHIS) argued minimum-age gates only delay rather than prevent the attack, and that delaying legitimate updates may itself introduce operational risk that outweighs the benefit in many organizations.
MITRE ATT&CK techniques used in TL-2026-1491
Collection
T1005 Data from Local System; T1113 Screen Capture
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1620 Reflective Code Loading
Credential Access
T1056 Input Capture; T1555 Credentials from Password Stores
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery
Initial Access
Impact
Persistence
T1505 Server Software Component; T1546 Event Triggered Execution
Resource Development
T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Affected products and versions in "Download Pumping"
- npm, Inc. / npm public registry — npm package registry (registry.npmjs.org) and dependent automated infrastructure (mirrors, security scanners, analysis bots)
Vulnerable versions: all versions of npm registry lifecycle-script/version-publish infrastructure as of 2026-02 - npm ecosystem — ambar-src (malicious npm package, typosquat of ember-source)
Vulnerable versions: 1 through 724 (malicious payload introduced in the version published 2026-02-16 12:18:45 UTC)
Fixed in: removed from registry entirely 2026-02-16 17:02:44 UTC - Multiple package-registry operators — PyPI, RubyGems, NuGet (registries described by researchers as architecturally comparable/similarly exposed; no confirmed exploitation reported)
Vulnerable versions: automated mirror/scanner infrastructure generally
Remediation for "Download Pumping"
Patches
- No vendor patch applicable — 'ambar-src' was removed from the npm registry by npm within ~4h44m of the malicious version's publication (2026-02-16 12:18:45 UTC to 17:02:44 UTC)
Immediate actions
- Treat any host that ran `npm install ambar-src` (or resolved it transitively) as fully compromised; do not attempt in-place cleanup
- Rotate all secrets, API keys, tokens, and credentials stored on or accessible from an affected host, performed from a separate, known-clean machine
- Block outbound connections to x-ya[.]ru, function.yandexcloud[.]ru, and the identified functions.yandexcloud.net URL paths
- Search EDR/process telemetry for msinit.exe, the ELF binary 'osa', reverse_ssh process indicators, and osascript spawning unexpected child processes or network connections
- Audit npm lockfiles and CI/CD dependency trees for 'ambar-src' or any package with an unexplained sudden spike (100s) of version publishes in a short window
Workarounds
- Configure npm/yarn/pnpm to respect a package minimum-age threshold where supported before allowing install of newly published versions
- Use internal registry proxies/mirrors with allowlisting so newly published packages require manual/automated security review before becoming installable org-wide
Longer-term hardening
- Enforce a minimum package-age gate (3-4+ days) before a newly published registry version is permitted in CI/CD or production builds
- Adopt version pinning / lockfile-only installs and disable automatic minor/patch version resolution in build pipelines
- Replace long-lived npm/CI publish and consumption tokens with ephemeral, just-in-time scoped credentials
- Apply least-privilege egress network policy to CI/CD runners and developer build environments to limit preinstall/postinstall script network access
- Do not use raw download counts, version-history density, or publish-frequency as trust/legitimacy signals in internal tooling or AI-assisted package recommendation logic
- Strengthen maintainer account authentication (mandatory 2FA/WebAuthn) on registry publish accounts
Weaknesses (CWE) in "Download Pumping"
Timeline of "Download Pumping"
- Independent researcher publicly demonstrates direct tarball-URL HTTP request flooding to spoof npm download counts, generating roughly 1 million spoofed downloads weekly — the precursor abuse pattern Tenable later revalidated
- Cybernews, Security Boulevard, DevOps.com, and other outlets report on the ambar-src incident and its 50,000-download compromise
- Tenable publishes its technical FAQ/analysis on the ambar-src malicious package, detailing platform-specific payloads, hashes, and C2 infrastructure
- The 'ambar-src' package (typosquatting 'ember-source') is first published to the npm registry; 428 benign-looking versions are uploaded within the first two hours
- By the time of removal and continuing to be tallied over the following days, ambar-src reaches 724 total published versions and approximately 50,000 downloads with zero legitimate users
- npm removes ambar-src from the public registry at 17:02:44 UTC, roughly 4 hours 44 minutes after the malicious version's publication
- A weaponized version of ambar-src is published at 12:18:45 UTC, containing a hex-encoded preinstall script that fetches OS-specific payloads from x-ya[.]ru
- Tenable researcher Ron Popov publishes the broader 'download pumping' research, generalizing the ambar-src version-flooding pattern into a named technique and publishing proof-of-concept download-amplification measurements
- ReversingLabs publishes 'Download pumping joins the trust-abuse bandwagon', crediting Tenable/Popov, summarizing the technique for a broader audience and noting industry pushback on minimum-age mitigations from James Shank (Expel) and John Strand (BHIS)
Sources cited for "Download Pumping"
- 'Download pumping' joins the trust-abuse bandwagon | RL Blog
- Download pumping: How threat actors use new npm deception technique in supply chain attacks | Tenable
- New malicious npm package 'ambar-src' targets developers with open source malware | Tenable Cybersecurity Research FAQ
- New Malicious npm Package 'ambar-src' Targets Developers with Open Source Malware - Security Boulevard
- Download pumping: New npm deception technique for supply chain attacks - Security Boulevard
- Mistype can lead to catastrophe: malicious NPM package with 50K downloads leads to full compromise - Cybernews
- Malicious Package in ambar-src | Snyk Vulnerability DB
- New malicious npm package 'ambar-src' targets developers with open source malware - Threat Radar | OffSeq.com
- New Malicious npm Package Highlights the Speed at Which Supply Chain Risks Propagate
- Malicious NPM Package Gets Downloaded 50K Times Before Discovery - DevOps.com
Detection coverage for TL-2026-1491
As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1491 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.