LWA-2026-11959 confirmed malware

btree-order-book@1.0.1

Malicious code in btree-order-book (npm)

Analysis

btree-order-book is a limit-order-book matching engine that depends on indexed-btree, a package previously identified as malicious. Installing btree-order-book transitively installs the known-malicious indexed-btree dependency. The package code itself is a straightforward TypeScript trading engine with no obfuscation or exfiltration, but its dependency chain introduces a supply-chain risk: any malicious behaviour in indexed-btree (postinstall payload, token theft, etc.) would execute in the context of the installer.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 12:50 AM
analyzed
Jul 15, 2026, 12:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.