Skip to content

Topic

npm malware

Malicious packages published to the npm JavaScript registry, typically through typosquatting, impersonation or compromised maintainer accounts.

Current clusters

security3 publishers

Malicious npm package indexed-btree fires its loader from a runtime library call

Checkmarx says a fake sorted-btree clone reached 2 million weekly downloads with clean install scripts, starting its loader only when an application calls BTree.prototype.set with a particular key. Nine related packages have been pulled.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 45%
Investor
Investor 12%

Reality

Evidence62
Adoption45
Hype gap+20
Incentives45
Confidence60