Skip to main content
CyberSingle-sourceHighDevelopingFeatured
6.7

Malicious NPM Package 'indexed-btree' Masquerades as 'sorted-btree', Millions of Downloads

A malicious NPM package named 'indexed-btree' has been observed impersonating the legitimate 'sorted-btree' library, embedding a malware trigger within a prototype method. The package has accumulated millions of downloads, indicating a significant supply-chain attack. The full scope of the compromise and the payload's behavior remain under investigation.

SecurityWeekabout 7 hours agoengCredibility 26%View source

Score Breakdown

Mosaic Score6.7
Confidence0.5
Significance0.8
Source credibility0.3
Source

Related signals

8 found