← All articles

Malicious npm package hides loader in runtime method to bypass install script controls

Checkmarx found an ongoing npm campaign built around indexed-btree, a package impersonating the popular sorted-btree library that has amassed two million weekly downloads. Instead of using preinstall or postinstall scripts, the malware hides its loader inside the BTree.prototype.set method that applications call constantly, so it executes at runtime rather than install time. This sidesteps the npm approval gates GitHub added in June to block lifecycle scripts, and installation looks clean to static scanners. Once triggered, it fingerprints the host, exfiltrates details over hardcoded Slack and Telegram channels, and polls an Ethereum Sepolia smart contract for encrypted second-stage commands.

Check
Audit dependency trees for indexed-btree and typosquats of sorted-btree, then remove them and rotate any credentials exposed to affected build or runtime hosts.
Affected
Projects that installed indexed-btree run the loader the first time application code calls the tree, giving attackers host fingerprinting and staged command execution.
Fix
Pin dependencies to reviewed versions, scan for runtime-triggered loaders not just install scripts, and block outbound Slack, Telegram, and testnet RPC from build hosts.