CyberHighSingle-sourceBuilding
6.8
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites via Compromised API Key
SecurityWeekLO·2 days ago
A campaign using the npm package 'indexed-btree' embeds malicious code in runtime behavior, bypassing defenses that scan install scripts. This marks a shift in supply-chain attack technique, as detection focused on pre-install hooks is insufficient. The full scope of affected packages and victims remains unclear.