Skip to main content
CyberSingle-sourceMediumDeveloping
4.8

npm 'indexed-btree' malware evades install-script defenses via runtime execution

A campaign using the npm package 'indexed-btree' embeds malicious code in runtime behavior, bypassing defenses that scan install scripts. This marks a shift in supply-chain attack technique, as detection focused on pre-install hooks is insufficient. The full scope of affected packages and victims remains unclear.

BleepingComputerabout 5 hours agoengCredibility 25%View source

Score Breakdown

Mosaic Score4.8
Confidence0.5
Significance0.5
Source credibility0.3

Intelligence Tags

Entities

concept
Source

Related signals

8 found