Malicious npm packages reportedly evade install-script defenses at runtime
BleepingComputer reports that a malware campaign involving the 'indexed-btree' package hides malicious code in normal package behavior rather than installation scripts.
TLDR
BleepingComputer describes an npm malware campaign involving 'indexed-btree' that bypasses supply chain defenses. According to the report, attackers hide malicious code in a package’s normal runtime behavior—what it does when it runs—instead of installation scripts.
Combined views
7.7K
1 Source, first seen 8h ago
Malicious npm packages reportedly evade install-script defenses at runtime
BleepingComputer reports that a malware campaign involving the 'indexed-btree' package hides malicious code in normal package behavior rather than installation scripts.
TLDR
BleepingComputer describes an npm malware campaign involving 'indexed-btree' that bypasses supply chain defenses. According to the report, attackers hide malicious code in a package’s normal runtime behavior—what it does when it runs—instead of installation scripts.