[SECURITY]■ STORY TIMELINE
NPM MALWARE BYPASSES INSTALL DEFENSES
A malicious npm campaign demonstrates how threat actors are evading supply chain protections by embedding malware in package runtime behavior instead of installation scripts. The 'indexed-btree' package exemplifies this evolving attack technique.
Bleeping Computer+0m
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defens…