
Malicious npm Package 'indexed-btree' Disguised as Legitimate Utility
Researchers from Checkmarx have identified a malicious npm package named 'indexed-btree' that impersonated the legitimate 'sorted-btree' package. The threat actor concealed malicious loader code within runtime application logic rather than using traditional npm lifecycle scripts, suggesting a tactical shift to evade security controls. The package has since been removed from the npm registry.
