chiprook
← Security
SecuritySeptember 20, 2026, 21:11

Malicious npm packages evade install-script defenses at runtime

Checkmarx found the npm package indexed-btree masquerading as sorted-btree: a malicious loader hidden in BTree.prototype.set() runs at runtime without install scripts. The package reached 2 million weekly downloads; nine related packages were found and removed from npm.

Malicious npm packages evade install-script defenses at runtime
#Npm#Checkmarx#GitHub
Read next
Security

CrowdSec confirms source code stolen in supply chain attack

Security

FBI: scammers impersonate police and demand payment under arrest threats

Security

Spain reports first end-to-end data breach carried out by an AI agent

Security

Iranian hackers suspected in attack on Hyundai Glovis tanker off Texas