# "Download Pumping" — npm Supply-Chain Trust-Signal Abuse via Mass Version Uploads (ambar-src / reverse_ssh / Apfell)

> Tenable researcher Ron Popov documented 'download pumping', a supply-chain deception technique in which attackers publish hundreds of package versions in rapid succession so that registry mirrors, security scanners, and analysis bots auto-download each release, artificially inflating download counts and version-history depth to fake legitimacy. The technique was proven in the wild via the malicious npm package 'ambar-src' (a typosquat of 'ember-source'), which reached 724 versions (428 in its first two hours) and ~50,000 downloads in three days before npm removed it, then dropped platform-specific malware (Windows: encrypted-shellcode loader; Linux: reverse_ssh; macOS: Apfell/MythicAgents) via a hex-encoded preinstall script.

- **Published:** 2026-07-18T00:00:00Z
- **Last reviewed:** 2026-07-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1491
- **ID:** TL-2026-1491
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In mid-February 2026 Tenable Research identified a malicious npm package, 'ambar-src', that typosquatted the popular 'ember-source' package (11M+ downloads). The package was first uploaded on 2026-02-13 and published as a series of benign-looking versions — 428 of them in the first two hours alone, eventually reaching 724 total versions — before a weaponized version was pushed on 2026-02-16 at 12:18:45 UTC. npm removed the package roughly 4h44m later (17:02:44 UTC the same day), but by then it had accumulated approximately 50,000 downloads with zero legitimate human users.

The malicious version abused npm's `preinstall` lifecycle script hook defined in package.json: merely running `npm install ambar-src`, or having it resolve transitively as a dependency, was sufficient to trigger the payload with no explicit `require()`/import needed. The `index.js` preinstall script executed a hex-encoded, OS-specific one-liner to obscure intent, and the package interspersed legitimate-looking utility code (MathUtils, StringUtils, time helpers) with the malicious logic to evade cursory review.

Platform-specific second-stage payloads were fetched from the attacker-controlled domain x-ya[.]ru: on Windows, an encrypted-shellcode loader (msinit.exe, ~400KB) decoded and executed the shellcode in memory; on Linux, a bash script pulled an ELF binary ('osa') identified via Golang build metadata as a variant of the open-source reverse_ssh backdoor; on macOS, a nohup-wrapped hex command invoked the native `osascript` utility to run a ~500KB JavaScript payload identified as Apfell, part of the MythicAgents C2 framework family, capable of reconnaissance, screenshot capture, Google Chrome credential/session data theft, and fake password-prompt phishing overlays. Command-and-control communications were relayed through Yandex Cloud Functions (function.yandexcloud[.]ru / functions.yandexcloud.net), abusing a well-known cloud service to blend in with legitimate traffic (MITRE T1102 Web Service).

Separately, and more broadly, Tenable's Ron Popov demonstrated the underlying 'download pumping' abuse pattern with proof-of-concept test packages: every new version publish triggers automated downloads from registry mirrors and security-scanner/analysis-bot infrastructure — 135.55 downloads/version for a plain version bump, 141.91 for a static postinstall script, and 158.16 for a dynamically-changing postinstall script, implying scanners preferentially re-fetch versions that look newly suspicious. Because scanners can often determine whether a postinstall script exists purely from package metadata (without downloading the tarball), attackers can game detection infrastructure itself into serving as an amplification network. Tenable also revalidated a 2021-era technique of direct tarball-URL HTTP request flooding, inflating a test package to 17,000 downloads in about one hour — showing the older method still works alongside the newer one. ReversingLabs' write-up (crediting Popov) and Tenable's own technical FAQ both note the underlying registry infrastructure pattern is not npm-specific: PyPI, RubyGems, and NuGet operate comparable automated-mirror/scanner ecosystems and are described as similarly exposed.

The attack is notable for its convergence with AI-assisted coding tools, which frequently use download counts, version-history density, and maintenance-activity signals as heuristics for package trustworthiness/recommendation — none of which were designed as security controls and all of which download pumping can fabricate cheaply. Recommended mitigations center on enforcing minimum package-age windows (3-4+ days) before a newly published version is eligible for use in CI/CD or production, alongside version pinning, least-privilege network egress for build/CI environments, ephemeral just-in-time credentials in place of long-lived tokens, and stronger maintainer/publish authentication. Dissenting industry voices (James Shank, Expel; John Strand, BHIS) argued minimum-age gates only delay rather than prevent the attack, and that delaying legitimate updates may itself introduce operational risk that outweighs the benefit in many organizations.

## MITRE ATT&CK

- T1584 Compromise Infrastructure
- T1585 Establish Accounts
- T1587 Develop Capabilities
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1546 Event Triggered Execution
- T1505 Server Software Component
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1620 Reflective Code Loading
- T1218 System Binary Proxy Execution
- T1082 System Information Discovery
- T1555 Credentials from Password Stores
- T1056 Input Capture
- T1113 Screen Capture
- T1005 Data from Local System
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1071 Application Layer Protocol
- T1491 Defacement

## Sources

- ['Download pumping' joins the trust-abuse bandwagon | RL Blog](https://www.reversinglabs.com/blog/download-pumping-trust-abuse)
- [Download pumping: How threat actors use new npm deception technique in supply chain attacks | Tenable](https://www.tenable.com/blog/how-cyberattackers-inflate-malicious-package-npm-download-counts)
- [New malicious npm package 'ambar-src' targets developers with open source malware | Tenable Cybersecurity Research FAQ](https://www.tenable.com/blog/cybersecurity-research-faq-new-malicious-npm-package-ambar-src)
- [New Malicious npm Package 'ambar-src' Targets Developers with Open Source Malware - Security Boulevard](https://securityboulevard.com/2026/02/new-malicious-npm-package-ambar-src-targets-developers-with-open-source-malware/)
- [Download pumping: New npm deception technique for supply chain attacks - Security Boulevard](https://securityboulevard.com/2026/05/download-pumping-new-npm-deception-technique-for-supply-chain-attacks/)
- [Mistype can lead to catastrophe: malicious NPM package with 50K downloads leads to full compromise - Cybernews](https://cybernews.com/security/malicious-npm-downloaded-by-thousands-of-developers/)
- [Malicious Package in ambar-src | Snyk Vulnerability DB](https://security.snyk.io/vuln/SNYK-JS-AMBARSRC-15286018)
- [New malicious npm package 'ambar-src' targets developers with open source malware - Threat Radar | OffSeq.com](https://radar.offseq.com/threat/new-malicious-npm-package-ambar-src-targets-develo-1c59a0c4)
- [New Malicious npm Package Highlights the Speed at Which Supply Chain Risks Propagate](https://smestreet.in/technology/new-malicious-npm-package-highlights-the-speed-at-which-supply-chain-risks-propagate-11161472)
- [Malicious NPM Package Gets Downloaded 50K Times Before Discovery - DevOps.com](https://devops.com/malicious-npm-package-gets-downloaded-50k-times-before-discovery/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1491
