Checkmarx identified npm package indexed-btree imitating sorted-btree with ~2M weekly downloads. It triggers its payload at runtime to bypass install-script protections, exposing developer environments to supply-chain compromise. #NpmSecurity #SupplyChainAttack #ThreatIntel
https://cyberworldops.eu/en/runtime-triggered-npm-malware-slips-past-install-script-protections
#npmsecurity
2 posts · Last used 17d
Replying to
@hacksilon@infosec.exchange PS. I like to add more hashtags to make it easier for people to find your post about malicious adform package.
#supplychain #supplychainsecurity #supplychainattack #npm #npmsecurity #ioc
You've seen all posts