Sophisticated Supply Chain Attack on npm Evolving Past Traditional Defenses with Smart Contract C2 and Runtime Malice
Executive Overview The JavaScript ecosystem has once again been rattled by a sophisticated, highly calculated software supply chain campaign targeting the npm (Node Package Manager) registry. Discovered and analyzed by security researchers at Checkmarx, the attack hinges on a malicious package named indexed-btree, which masquerades as a legitimate dependency (sorted-btree). Amassing nearly two million weekly…
