Malicious npm packages evade install-script defenses at runtime

  • Thread starter Thread starter Bill Toulas
  • Start date Start date
B

Bill Toulas

Guest
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

Continue reading...
 
Back
Top