CyberHighSingle-sourceDeveloping
7.1
Fake LastPass installers deploy kernel-level EDR killer and Rapuncel stealer
SecurityWeekLO·1 day ago
A campaign using the npm package 'indexed-btree' embeds malicious code in runtime behavior, bypassing defenses that scan install scripts. This marks a shift in supply-chain attack technique, as detection focused on pre-install hooks is insufficient. The full scope of affected packages and victims remains unclear.