security1 publisher
Malicious npm package indexed-btree fires its loader from a runtime library call
Checkmarx says a fake sorted-btree clone reached 2 million weekly downloads with clean install scripts, starting its loader only when an application calls BTree.prototype.set with a particular key. Nine related packages have been pulled.
Publishers:bleepingcomputer.com
Reality
- Evidence58
- Adoption58
- Hype gap+18
- Incentives70
- Confidence56