CuraSec

Plan active

Malicious npm packages evade install-script defenses at runtime

2026-09-20 14:41 UTC · BleepingComputer · read the source ↗ #supply-chain#npm#malware-evasion
  • Engineer — Plan: This evasion class specifically defeats install-hook-only defenses (e.g., –ignore-scripts, tools that only scan lifecycle scripts); audit whether your SCA/supply-chain tooling monitors runtime behavior, and check all dependency trees for the ‘indexed-btree’ package.
  • SOC/IR — Learn: The technique — embedding malicious logic in runtime code rather than install hooks — expands the detection surface for npm supply-chain attacks; no IOCs or TTPs are published here yet, but pipeline and CI runtime behavior monitoring becomes more relevant as a future detection investment.
  • Leader — Learn: Ongoing npm campaigns are evolving past basic supply-chain controls, reinforcing the case for mature SCA investment; no systemic or board-level event without corroborating signals, but useful context for software supply chain security program reviews.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.