← Back to the feed

~/article/malicious-npm-packages-evade-install-script-defenses-at-runtime-1c24ps
infoSource: BleepingComputer

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts.

Read at the source

Summary written for cymesh.dev. The full article lives at BleepingComputer.

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks