Episode Details

Back to Episodes

Malicious npm packages hide after installation and strike at runtime

Season 1 Episode 118 Published 1 week, 4 days ago
Description

Daily Cyber News: Malicious npm packages hide after installation and strike at runtime

Development teams can be compromised even when a package installation looks completely clean. In an ongoing N P M campaign, malicious code was placed inside the normal runtime behavior of the indexed-btree package instead of using installation scripts that newer defenses can block. The loader activates through a commonly used library method, but only when that method receives a specific key value.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, Malicious, packages, hide, installation, strike, runtime.

Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us