A malicious npm package that appeared to be an ordinary data-indexing tool has exposed a weakness in software supply-chain defenses. The package, indexed-btree, copied the identity of the legitimate sorted-btree library and recorded almost two million weekly downloads. The campaign is notable because the malware does not need to run while a... Weiterlesen
Intelligence View
Malicious npm Package With 2 Million Downloads Hides Malware in Runtime Code
A malicious npm package that appeared to be an ordinary data-indexing tool has exposed a weakness in software supply-chain defenses. The package, indexed-btree, copied the identity of the legitimate sorted-btree library and recorded almost…
SOCIAL SHARE CARD GENERATOR