Download Privacy Needle App

Type to search

Cybersecurity

Malicious npm Package indexed-btree Bypasses Security via Runtime Code

Share

A malicious npm package known as “indexed-btree” has been identified using runtime code to hide its malware loader, a tactic designed to bypass recent security enhancements in the Node Package Manager (npm) registry.

Researchers at Checkmarx discovered that the package, which mimics the legitimate “sorted-btree” utility, avoids using the preinstall or postinstall lifecycle scripts commonly used in supply chain attacks. This shift follows security changes in npm version 12, which were introduced to prevent the automatic execution of these scripts during installation.

Attackers Bypass Lifecycle Script Restrictions

Instead of relying on installation hooks, the malware hides its execution within existing application logic. Specifically, the loader is concealed inside a “BTree.prototype.set()” method. This trigger activates “sharedLoad.min.js”, a JavaScript payload that contains the first stage of the malware.

The malware is designed to fingerprint the host system and send details to a hard-coded Slack channel and a Telegram bot. It also utilises a technique known as “EtherHiding” to retrieve encrypted, second-stage payloads from a smart contract deployed on the Sepolia testnet. Once the payload is formed, the malware attempts to delete its malicious artefacts and remove the trigger from the package code to evade detection.

Financial Impact and Technical Execution

Statistics indicate the package amassed millions of downloads after its initial upload on 18 June 2026. The campaign is believed to have generated significant illicit profits, estimated at approximately €230,933.57 (roughly 109 ETH) in cryptocurrency.

Several other packages were identified as part of the same operation, including “ordered-kv-index”, “btree-leaderboard”, “priority-slot-queue”, and “btree-core”. These have since been removed from the npm registry.

Ensar Seker, CISO at SOCRadar, noted that the campaign demonstrates how attackers adapt almost immediately to stronger software supply chain defences. Seker suggested that while blocking lifecycle scripts is an important step, defenders must implement layered controls that include runtime behaviour analysis to detect malicious activity during execution.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.