⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

September 22, 2026

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal Ravie LakshmananSep 22, 2026Supply Chain Attack / Malware A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said. "Unlike the common attacks we've seen in the supply chain space, this package does not rely on preinstall / postinstall at all. Instead, it runs entirely from application code at runtime." The package and the associated GitHub repository are no longer available for download from npm. However, statistics…