Indexed-btree npm malware has been quietly accumulating 2 million weekly downloads by hiding its malicious payload inside a library method that fires at runtime rather than at install time, allowing it to sidestep the latest wave of npm supply chain protections entirely. daily.dev reports that npm removed the package on 3 September 2026, roughly 11 weeks after the first malicious version appeared.

The campaign was uncovered by Checkmarx researchers, who identified the package as an impersonator of the legitimate sorted-btree library. On the surface, nothing looks wrong: no suspicious install scripts, no unexpected network calls at setup time. That is precisely the point.

How indexed-btree npm malware bypasses npm v12 defences

In June 2026, GitHub announced a set of npm security measures aimed at preventing supply chain attacks. Among the most consequential: lifecycle scripts such as preinstall, install, and postinstall are now blocked unless explicitly approved by the developer. npm was also prevented from silently fetching dependencies from Git repositories or remote URLs.

The authors of indexed-btree simply ignored all of that. Instead of using install hooks, they buried their loader inside the package’s BTree.prototype.set() method, which is the core function any consumer of a B-tree library would call repeatedly during normal use. When the application calls that method with a specific key value, the loader fires, triggering sharedLoad.min.js, an obfuscated first-stage payload.

‘The malware loader hides inside the library’s own BTree.prototype.set method, which is the main function that every user would call constantly,’ Checkmarx explained. ‘This triggers the sharedLoad.min.js, which contains the obfuscated first stage of the malware. This is a well-built way to sneak past standard taint-analysis tools and most static scanners.’

Because execution happens at runtime rather than during installation, none of npm v12’s approval mechanisms are triggered. The install log looks clean. A routine dependency audit raises nothing.

Command-and-control via Ethereum and the Sepolia testnet

Once active, the malware collects system details including architecture, hostname, CPU, memory and uptime, then exfiltrates that information through hardcoded Slack and Telegram channels. For command-and-control (C2) instructions, it takes an unusual route: polling an Ethereum smart contract on the Sepolia test network.

According to Cybersecurity News, the smart contract address used is 0xE390863Dac96a7118C71227C2b099B50cF602D31. The malware uses X25519 key exchange to derive an AES key, which it then uses to decrypt a second-stage payload stored inside that contract. Using a public blockchain for C2 is a deliberate choice: blockchain transactions are immutable and the infrastructure cannot simply be taken offline the way a traditional command server can.

Checkmarx also noted a wallet holding 109 ETH connected to the operation, though the researchers did not state that those funds came from cryptocurrency theft.

When the operators decide to wrap up, the malware is designed to cover its tracks: it can delete its own files and remove the malicious trigger from the package code, leaving little evidence behind.

Nine linked packages, millions of downloads between them

Checkmarx discovered nine further npm packages tied to the same campaign, all of which have since been removed. Their combined download numbers are not trivial:

ordered-kv-index (448,184 downloads), btree-leaderboard (493,685), priority-slot-queue (402,860), btree-range-store (468,092), btree-core (1,951,274), btree-time-index (425,312), btree-lru-cache (372,185), neighbor-key-map (366,019), and sliding-score-window (448,024).

The threat actors went to considerable lengths to make the operation look credible, building a legitimate-looking GitHub repository for the package, populating its commit history, and cultivating the developer account over time.

What developers should do now

Checkmarx’s advice is clear: install-time scanning alone is not sufficient. Developers need runtime behavioural analysis alongside static checks, because a payload that only activates when called by application code will sail through any scanner that stops at the installation boundary.

Anyone who installed indexed-btree or any of the nine linked packages should rotate all secrets immediately and restore their development environment from a clean, verified backup. With the packages now removed from npm and the takedown confirmed, the window for new infections has closed, but environments that pulled these packages in during that 11-week window remain at risk until remediated.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version