New npm malware finds a way around install script defenses
Blocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies used in software supply-chain attacks. Security researchers at Checkmarx are warning of attackers using a malicious package called “indexed-btree” to impersonate the legitimate sor…
Read the full story at InfoWorld AI ↗
Timeline · 1 report
- 2026-09-21 14:24 · InfoWorld AI
New npm malware finds a way around install script defenses