Download pumping: New npm deception technique for supply chain attacks

2026-05-28T20:52:22Z5b7b6deb4c58af5b11b462edb637feb073a845851975ec0d64966c1489d73bc7
CI/CD compromiseCVE-2026-9082Hexa AIMini Shai-HuludMistral AIOpenAIPostgreSQLPyPISLSA provenance bypassSQL injectionTeamPCPTenable Onecredential theftdownload inflationdownload pumpingdrupalexploitationexposure managementnpmpackage poisoningpackage registry mirrorsself-propagating wormsoftware supply chainsupply-chain malwarethreat intelligence

What happened

This Tenable Blog feed highlights multiple high-risk supply chain and exposure-management issues: (1) “Download pumping” — attackers are inflating npm package download counts by rapidly publishing many benign versions to trigger automated downloads from mirrors/scanners, then later pushing malicious releases to hide payloads and deceive developers; (2) Mini Shai‑Hulud (TeamPCP) — a self‑propagating worm that has compromised >170 npm/PyPI packages, stolen developer/cloud credentials, defeated SLSA provenance attestations, and used CI/CD pipelines to propagate poisoned packages (any system that,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
5b7b6deb4c58af5b11b462edb637feb073a845851975ec0d64966c1489d73bc7
Enrichment time
2026-05-28T20:52:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.