URL has been copied successfully!
Malicious npm packages evade install-script defenses at runtime
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts.

First seen on bleepingcomputer.com

Jump to article: www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link