{"id":10773,"date":"2026-02-27T03:02:23","date_gmt":"2026-02-27T03:02:23","guid":{"rendered":"https:\/\/mailitics.com\/index.php\/2026\/02\/27\/tenable-warns-of-supply-chain-attack-on-npm-registry-2845520\/"},"modified":"2026-02-27T03:02:23","modified_gmt":"2026-02-27T03:02:23","slug":"tenable-warns-of-supply-chain-attack-on-npm-registry-2845520","status":"publish","type":"post","link":"https:\/\/mailitics.com\/index.php\/2026\/02\/27\/tenable-warns-of-supply-chain-attack-on-npm-registry-2845520\/","title":{"rendered":"Tenable warns of supply chain attack on npm Registry"},"content":{"rendered":"<p>    Tenable warns of supply chain attack on npm Registry<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<img data-recalc-dims=\"1\" decoding=\"async\" class=\"img-responsive\" src=\"https:\/\/i0.wp.com\/d1v1e13ebw3o15.cloudfront.net\/data\/92179\/pool_and_spa_logo\/..jpg?ssl=1\"> <\/p>\n<p><a href=\"https:\/\/www.tenable.com\/\" target=\"_blank\" rel=\"noopener\">Tenable Research<\/a> has uncovered a supply chain attack on the npm Registry which the company said demonstrates the speed at which modern supply chain risks can propagate.<\/p>\n<p>The npm Registry is a public collection of packages of open-source code for Node.js, including front-end web apps, mobile apps, robots, routers and other tools used by JavaScript developers.<\/p>\n<p>The attack uncovered by Tenable researchers involved uploading a malicious package to the registry that was designed to mimic a popular existing package to infect developers\u2019 systems across Windows, macOS and Linux. In the mere five hours before it was removed, the malicious package was downloaded around 50,000 times, Tenable Research said. The threat is unique in that it did not require a developer to run any code to fall victim to the attack.<\/p>\n<p>The moment a command to install the package is typed, a hidden preinstall script automatically runs in the background and is used to identify the victim\u2019s system and install the malware.<\/p>\n<p>Unlike legitimate software that has been compromised, the spoofed program\u2019s only purpose is to deliver the malware, according to Tenable Director for Research Ari Eitan. The malware also uses multiple techniques to evade detection, and the installed malware is capable of exfiltrating sensitive data including screenshots and passwords.<\/p>\n<p>\u201cDevelopers often assume that if a package is available on a public registry it is safe to download,\u201d he said.\u00a0\u201cBy hiding the attack inside the installation process, hackers ensure they are inside your system before you\u2019ve even had a chance to verify the code,\u201d he said.<\/p>\n<p>More information about amber-src can be found <a href=\"https:\/\/www.tenable.com\/blog\/cybersecurity-research-faq-new-malicious-npm-package-ambar-src\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<p><h9>Image credit: iStock.com\/ATHVisions<\/h9><\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><\/p>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.technologydecisions.com.au\/content\/security\/news\/tenable-warns-of-supply-chain-attack-on-npm-registry-2845520?utm_source=rss\">Go to Technology Decisions<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tenable warns of supply chain attack on npm Registry Tenable Research has uncovered a supply chain attack on the npm Registry which the company said demonstrates the speed at which modern supply chain risks can propagate. The npm Registry is a public collection of packages of open-source code for Node.js, including front-end web apps, mobile [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[44],"tags":[48],"class_list":["post-10773","post","type-post","status-publish","format-standard","hentry","category-technology-decisions","tag-technology-decisions"],"_links":{"self":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/posts\/10773"}],"collection":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/comments?post=10773"}],"version-history":[{"count":0,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/posts\/10773\/revisions"}],"wp:attachment":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/media?parent=10773"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/categories?post=10773"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/tags?post=10773"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}