A malicious npm package named indexed-btree, presented as the legitimate sorted-btree package, accumulated millions of downloads, SecurityWeek reported. The package reportedly hid a malware trigger in a prototype method.

Development and security teams should search dependency inventories and lockfiles for the package, remove it where present, rotate exposed secrets as appropriate, and review build and runtime telemetry. Pinning dependencies and using registry and software-composition controls can reduce similar supply-chain risk.

Source: SecurityWeek.

By Allan