A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said. "
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
About this summary. This is a short, independently written summary of an article first published by The Hacker News. Cyber Security News did not report or verify the underlying story. Read the original: https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html

Source attribution: headline and facts are from The Hacker News (thehackernews.com). Summary method: excerpt of the source description. See our source attribution policy.






