Reposted by Sabotage
Malicious npm packages evade install-script defenses at runtime #cybersecurity #hacking #news #infosec #security #technology #privacy
bleepingcomputer.com
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts.