Plan
active
Malicious npm packages evade install-script defenses at runtime
- Engineer — Plan: This evasion class specifically defeats install-hook-only defenses (e.g., –ignore-scripts, tools that only scan lifecycle scripts); audit whether your SCA/supply-chain tooling monitors runtime behavior, and check all dependency trees for the ‘indexed-btree’ package.
- SOC/IR — Learn: The technique — embedding malicious logic in runtime code rather than install hooks — expands the detection surface for npm supply-chain attacks; no IOCs or TTPs are published here yet, but pipeline and CI runtime behavior monitoring becomes more relevant as a future detection investment.
- Leader — Learn: Ongoing npm campaigns are evolving past basic supply-chain controls, reinforcing the case for mature SCA investment; no systemic or board-level event without corroborating signals, but useful context for software supply chain security program reviews.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.