Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
Security

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

The Hacker News · Sep 22, 2026

Back to News
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
Security September 22, 2026

A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said. "

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.