Malicious npm Package indexedbtree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named indexedbtree has been observed hiding its malicious behavior within application code rather than using lifecycle scripts indicating that threat actors are likely shifting tactics in response to recent security controls Indexedbtree is a malicious npm package mimicking the legit sortedbtree package an ordinary Btreeindexing utility Checkmarx said