Malicious npm Packages Evade Install-Script Defenses at Runtime
Threat actors are using the 'indexed-btree' npm package to bypass supply chain defenses by hiding malicious code in runtime behavior rather than installation scripts, complicating detection.