Malicious npm packages evade install-script defenses at runtime
Block install scripts and attackers just move the payload into a method you actually call. Checkmarx found 10 npm packages hiding malware in BTree.prototype.set() — indexed-btree alone pulled 2 million weekly downloads — with C2 spread across Slack, Telegram and an Ethereum contract, plus a fake GitHub repo to match. All pulled from npm now. If your supply-chain check stops at “no preinstall hook”, it is checking last year’s attack.