#5
BleepingComputer
general
September 20, 2026 at 14:11 UTC
Malicious npm packages evade install-script defenses at runtime
By Bill Toulas
AI Summary
An ongoing npm supply chain campaign using the 'indexed-btree' package demonstrates a technique to evade install-script-based defenses by embedding malicious behavior in normal runtime code paths rather than postinstall hooks. This approach bypasses controls implemented by npm and many CI/CD pipelines that focus on flagging suspicious install scripts.
Relevance score: 76.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →