A malicious npm package called indexed-btree illustrates a sharper supply-chain trick: hiding bad behavior in normal runtime code, beyond the reach of install-script checks.
A packaging shift in Android malware is making store review and basic scanning less useful, while vendor telemetry points to fewer blocked mobile attacks in Q2 than in Q1.