Malicious npm packages reportedly evade install-script defenses at runtime
BleepingComputer reports that a malware campaign involving the 'indexed-btree' package hides malicious code in normal package behavior rather than installation scripts.
TLDR
BleepingComputer describes an npm malware campaign involving 'indexed-btree' that bypasses supply chain defenses. According to the report, attackers hide malicious code in a package’s normal runtime behavior—what it does when it runs—instead of installation scripts.
Combined views
21.5K
3 Sources, first seen ago
77 likes6 comments17 saves31 reposts