CyberNotableSingle-sourceDeveloping
4.8
npm 'indexed-btree' malware evades install-script defenses via runtime execution
BleepingComputerLO·2 days ago
A malicious NPM package named 'indexed-btree' has been observed impersonating the legitimate 'sorted-btree' library, embedding a malware trigger within a prototype method. The package has accumulated millions of downloads, indicating a significant supply-chain attack. The full scope of the compromise and the payload's behavior remain under investigation.