← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 20, 2026 · 14:11via BleepingComputer

Malicious npm packages evade install-script defenses at runtime

Brief

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [... ]

Read more on BleepingComputer→