Download pumping: New npm deception technique for supply chain attacks
2026-05-28T20:52:22Z•5b7b6deb4c58af5b11b462edb637feb073a845851975ec0d64966c1489d73bc7
CI/CD compromiseCVE-2026-9082Hexa AIMini Shai-HuludMistral AIOpenAIPostgreSQLPyPISLSA provenance bypassSQL injectionTeamPCPTenable Onecredential theftdownload inflationdownload pumpingdrupalexploitationexposure managementnpmpackage poisoningpackage registry mirrorsself-propagating wormsoftware supply chainsupply-chain malwarethreat intelligence
What happened
This Tenable Blog feed highlights multiple high-risk supply chain and exposure-management issues: (1) “Download pumping” — attackers are inflating npm package download counts by rapidly publishing many benign versions to trigger automated downloads from mirrors/scanners, then later pushing malicious releases to hide payloads and deceive developers; (2) Mini Shai‑Hulud (TeamPCP) — a self‑propagating worm that has compromised >170 npm/PyPI packages, stolen developer/cloud credentials, defeated SLSA provenance attestations, and used CI/CD pipelines to propagate poisoned packages (any system that,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 5b7b6deb4c58af5b11b462edb637feb073a845851975ec0d64966c1489d73bc7
- Enrichment time
- 2026-05-28T20:52:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.