← Cybersecurity
CYBER BleepingComputer

Malicious npm packages evade install-script defenses at runtime

BleepingComputer / PUBLISHER FEED IMAGE

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts.

PUBLISHER-PROVIDED PREVIEW

This in-site reader presents the headline and limited excerpt supplied through the publisher’s feed. The original reporting remains with BleepingComputer.