CuraSec

Plan active

Malicious npm Package indexed-btree Hid Loader in Runtime Code

2026-09-22 15:30 UTC · The Hacker News · read the source ↗ #supply-chain#npm#malware
  • Engineer — Plan: Audit lock files and build artifacts for indexed-btree (a typosquat of sorted-btree); more broadly, review whether your static analysis and SCA tooling scans runtime-embedded code, not just lifecycle scripts, since this tactic shift evades install-hook detections.
  • SOC/IR — Learn: The shift from lifecycle-script loaders to runtime-embedded payloads is a meaningful detection-evasion evolution worth tracking — no IOCs or ATT&CK-mappable TTPs were published, so no immediate hunt is actionable.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.