SECURITY·중요도 8·2026. 09. 22.·The Hacker News

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

── KO ──────────────────

악성 npm 패키지 'indexed-btree'가 런타임 코드에 악성 코드를 숨겼다는 경고가 발표됐다.

악성 npm 패키지 'indexed-btree'가 애플리케이션 코드 안에 악성 행동을 숨기는 방식으로 최근 보안 대책에 대응하고 있다는 경고가 제기됐다. 이 패키지는 합법적인 'sorted-btree' 패키지를 모방하고 있으며, Checkmarx는 이를 지적했다. 공격자가 언어 주기를 이용하는 대신 런타임에서 코드를 숨기는 경향을 보이고 있다.


── EN ──────────────────

A malicious npm package 'indexed-btree' is hiding its malicious actions within runtime code.

The malicious npm package 'indexed-btree' has been discovered to conceal its malicious behavior within application code instead of using lifecycle scripts. This indicates that threat actors are adapting their tactics in response to recent security measures. The package mimics the legitimate 'sorted-btree' package, as noted by Checkmarx.

원문 보기 →목록으로