G Graphene OS News Mobile security, privacy, Android hardening, and open-source ecosystem news.
Log in Register Editor
EN RU DE PL ES
Back to latest

Security / BleepingComputer

Malicious npm packages evade install-script defenses at runtime

1 min read

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

This portal shows a short summary and attribution. Follow the original source for the complete article.

Open original source