:
[SECURITY]■ STORY TIMELINE

NPM MALWARE BYPASSES INSTALL DEFENSES

A malicious npm campaign demonstrates how threat actors are evading supply chain protections by embedding malware in package runtime behavior instead of installation scripts. The 'indexed-btree' package exemplifies this evolving attack technique.

1 SOURCEFIRST SEEN SEP 20, 02:11 PM► READ THE ARTICLE
Bleeping Computer+0m

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defens…