Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: malware (2 articles)Clear

Malicious npm package hides loader in runtime method to bypass install script controls

Checkmarx found an ongoing npm campaign built around indexed-btree, a package impersonating the popular sorted-btree library that has amassed two million weekly downloads. Instead of using preinstall or postinstall scripts, the malware hides its loader inside the BTree.prototype.set method that applications call constantly, so it executes at runtime rather than install time. This sidesteps the npm approval gates GitHub added in June to block lifecycle scripts, and installation looks clean to static scanners. Once triggered, it fingerprints the host, exfiltrates details over hardcoded Slack and Telegram channels, and polls an Ethereum Sepolia smart contract for encrypted second-stage commands.

Check
Audit dependency trees for indexed-btree and typosquats of sorted-btree, then remove them and rotate any credentials exposed to affected build or runtime hosts.
Affected
Projects that installed indexed-btree run the loader the first time application code calls the tree, giving attackers host fingerprinting and staged command execution.
Fix
Pin dependencies to reviewed versions, scan for runtime-triggered loaders not just install scripts, and block outbound Slack, Telegram, and testnet RPC from build hosts.

WhatsApp malware spreads fake invoices that install remote-access admin tools

Kaspersky is tracking an active campaign that spreads through WhatsApp by hijacking real accounts and sending their contacts a script file disguised as a business or financial document, with no accompanying message. If a Windows user opens it, the script disables User Account Control protections and silently installs ManageEngine Endpoint Central, a legitimate IT remote-management tool, configured to connect to attacker servers and hand them remote control of the machine. Using trusted contacts and signed, legitimate software helps the attack slip past suspicion and many security tools. The campaign spans several countries, with most confirmed victims in Malaysia, and how the WhatsApp accounts are compromised is still unknown.

Check
Warn staff to treat unexpected document or invoice files sent over WhatsApp as suspect, even from known contacts, and watch for remote-management tools installed outside approved IT processes.
Affected
Windows users who receive and open script files sent through compromised WhatsApp contacts; the campaign is global, with most confirmed victims in Malaysia, and abuses legitimate remote-management software for access.
Fix
Verify unexpected files through a separate channel before opening, block script attachments, allowlist approved remote-management software and alert on unauthorized installs, and keep User Account Control enabled with endpoint protection active.