New Malicious npm Package Highlights the Speed at Which Supply Chain Risks Propagate Tenable Research investigated a malicious package in the npm public registry named “amber-src” that underscores the rapid nature of modern supply chain attacks. The package, which was downloaded approximately 50,000 times before February 26, 2026 News/Technology News