Home / Sep 21, 2026 / Story
0
#5 BleepingComputer general September 20, 2026 at 14:11 UTC

Malicious npm packages evade install-script defenses at runtime

By Bill Toulas

AI Summary

An ongoing npm supply chain campaign using the 'indexed-btree' package demonstrates a technique to evade install-script-based defenses by embedding malicious behavior in normal runtime code paths rather than postinstall hooks. This approach bypasses controls implemented by npm and many CI/CD pipelines that focus on flagging suspicious install scripts.

Relevance score: 76.0/100

# More from September 21