The record
Written from the 1 report below. Nothing here is unsourced.
- A malicious npm package named indexed-btree was discovered distributing malware by hiding code within runtime functions rather than traditional installation scripts.
- The package successfully evaded new npm security controls that block automatic execution during package setup.
- Attackers also used the EtherHiding technique to retrieve second-stage payloads from a blockchain smart contract.
- This development highlights that security hardening in package managers leads threat actors to adopt more sophisticated, runtime-based execution methods.
What to watch next
- Continued evolution of runtime-based malicious execution in software packages
- Further use of blockchain-based staging techniques like EtherHiding and NullReceiver
- Additional compromises related to the PolinRider campaign targeting developer environments
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Ensar Seker
CISO at SOCRadar
2 quotes · 1 outlet
“What makes this campaign particularly important is that it shows attackers adapting almost immediately to stronger software supply chain defenses”
In the article
…- sliding-score-window - mutex-forge To counter the threat, developers are recommended not to stick only to install-time scanning and blocking lifecycle scripts alone, but also employ runtime behavior analysis. " What makes this campaign particularly important is that it shows attackers adapting almost immediately to stronger software supply chain defenses ," Ensar Seker, CISO at SOCRadar, said in a statement shared with The Hacker News. "Npm has improved install time security by restricting dependency lifecycle scripts, but this campaign demonstrates that attackers can…
“The broader lesson is that security controls change attacker behavior rather than eliminate the underlying threat.”
In the article
…has improved install time security by restricting dependency lifecycle scripts, but this campaign demonstrates that attackers can simply move malicious execution into legitimate-looking runtime functionality instead." " The broader lesson is that security controls change attacker behavior rather than eliminate the underlying threat. Blocking lifecycle scripts is an important improvement, but attackers will continue searching for alternative execution paths. Defenders, therefore, need layered controls capable of detecting malicious behavior before…
Coverage1
All filed from India
Named North Korea · indexed-btree · npm · visanduma/nova-two-factor · charlessadler25 · Checkmarx · Ensar Seker · Karlo Zanki · PolinRider · Socket · SOCRadar
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
