Skip to main content
See every side of every news story
Published loading...Updated

New Npm Malware Finds a Way Around Install Script Defenses

Summary by CSO Online
Blocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies used in software supply-chain attacks. Security researchers at Checkmarx are warning of attackers using a malicious package called “indexed-btree” to impersonate the legitimate sorted-btree library, to spread malware hidden in the package’s normal runtime code. The campaign abandons the preinstall and postinstall scripts common …

11 Articles

Checkmarx Zero has released a new attack on npm packages. The most worrying thing is that the latest security measures deployed in npm v12 are already partially bypassed and especially the preinstall and postinstall restrictions. The compromise code hides in a non-compromising function to run when the code is actually used...The case studied by Checkmarx Zero researchers concerns the npm indexed-btree package, which has reached nearly 2 million …

Global Security Mag OnlineGlobal Security Mag Online
Reposted by
Global Security Mag OnlineGlobal Security Mag Online

Attackers bypass new npm protections... by moving the malware from installation to execution A new malicious campaign analyzed by Checkmarx Zero shows how attackers adapt to the restrictions introduced by npm on preinstall and postinstall scripts. Malwares / Malware

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in Melville, United States on Sunday, September 20, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal