> Malicious npm packages evade install-script defenses at runtime
[AUTHOR: Bill Toulas]
[DATE: 20/09/2026 14:11]
[LANGUAGE: EN]
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]