importantSYS.SOURCE: The Hacker News• 2026-09-22T15:08:18+05:30
Malicious npm Package 'indexed-btree' Conceals Runtime Loader Before Removal
A malicious npm package named 'indexed-btree' concealed its loader within runtime code rather than using lifecycle scripts, bypassing recent security controls. The package, which generated over €230k in illicit cryptocurrency, highlights evolving supply chain attack techniques that shift execution to runtime functionality.
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.
"Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said. "
*** END OF TRANSMISSION ***