Malicious npm packages hide after installation and strike at runtime
Daily Cyber News: Malicious npm packages hide after installation and strike at runtime
Development teams can be compromised even when a package installation looks completely clean. In an ongoing N P M campaign, malicious code was placed inside the normal runtime behavior of the indexed-btree package instead of using installation scripts that newer defenses can block. The loader activates through a commonly used library method, but only when that method receives a specific key value.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, Malicious, packages, hide, installation, strike, runtime.