build1 publisher
Malicious npm package fires its loader from inside BTree.prototype.set()
Checkmarx found that indexed-btree declares no lifecycle hooks and starts its loader when application code calls set() with key 100. The loader reads its C2 address from a smart contract on Ethereum Sepolia.
Publishers:dev.to
Reality
- Evidence58
- Adoption38
- Hype gap+18
- Incentives62
- Confidence57