LWA-2026-11959 confirmed malware
btree-order-book@1.0.1
Malicious code in btree-order-book (npm)
Analysis
btree-order-book is a limit-order-book matching engine that depends on indexed-btree, a package previously identified as malicious. Installing btree-order-book transitively installs the known-malicious indexed-btree dependency. The package code itself is a straightforward TypeScript trading engine with no obfuscation or exfiltration, but its dependency chain introduces a supply-chain risk: any malicious behaviour in indexed-btree (postinstall payload, token theft, etc.) would execute in the context of the installer.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 12:50 AM
- analyzed
- Jul 15, 2026, 12:55 AM
Related advisories
- btree-order-book@1.0.0 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.