An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts.
Malicious npm packages evade install-script defenses at runtime
About this summary. This is a short, independently written summary of an article first published by BleepingComputer. Cyber Security News did not report or verify the underlying story. Read the original: https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/

Source attribution: headline and facts are from BleepingComputer (bleepingcomputer.com). Summary method: excerpt of the source description. See our source attribution policy.






