Research · InfosecFeed Brief
Malicious npm packages evade install-script defenses at runtime
What you need to know
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]
Source transparency
Read the original report at BleepingComputer ↗
This is an InfosecFeed curated brief based on reporting from BleepingComputer. InfosecFeed does not claim ownership of the original reporting.