Malicious B-tree NPM Package Accumulates Millions of Downloads
Malicious NPM package 'indexed-btree' with millions of downloads hides malware in prototype code.
Summary
A malicious NPM package named 'indexed-btree' has accumulated millions of downloads by impersonating a legitimate utility. The threat actor hid malware within the package's prototype method, bypassing detection systems. This campaign utilizes a blockchain contract for command and control and has been linked to other packages with significant download counts.
Full text
The NPM ecosystem has suffered another supply chain attack in which a malicious package has accumulated millions of downloads, Checkmarx reports. Still ongoing, the campaign has managed to bypass NPM’s recent protections by hiding a malicious trigger in the package’s JavaScript prototype code, rather than using an install script that could be detected by security solutions. Instead of targeting highly popular packages for fast propagation, and likely immediate detection, the threat actor built trust by creating a legitimate-looking GitHub repository. The malicious package, indexed-btree, mimics the legitimate B-tree/indexing utility sorted-btree, and has reached 2 million weekly downloads before being detected, Checkmarx says. To ensure the package’s popularity, the threat actor created a GitHub account and added seemingly legitimate commits to the indexed-btree repository. “A GitHub repository is something that attackers don’t usually bother creating. This one is clever enough to not include the malicious code. Additionally, the presence of many commits can aid in making it look like a legit repository,” Checkmarx notes.Advertisement. Scroll to continue reading. The threat actor hid malicious code in the library’s main function, the BTree.prototype.set method, to trigger JavaScript code containing the malware’s first stage. Once executed, the malware collects system information and sends it to a hardcoded Slack channel and Telegram chat, connects to a blockchain contract deployed on Sepolia that serves as its command-and-control (C&C), extracts and decrypts the second stage from the contract, and cleans its traces. According to Checkmarx, the attacker’s smart contract was previously found in the mutex-forge package, and the threat actor appears to have made 109 ETH (nearly $300,000). In addition to indexed-btree, other packages linked to the supply chain campaign include ordered-kv-index, btree-leaderboard, priority-slot-queue, btree-range-store, btree-core, btree-time-index, btree-lru-cache, neighbor-key-map, and sliding-score-window, which had over 5 million downloads when removed. “This ongoing campaign is a dynamic threat to organizations, with a resilient C&C and malicious code hidden inside package code,” Checkmarx notes. Related: Rust Team Members and Popular Crate Owners Targeted via Video Calls Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Related: Rust Supply Chain Attack Linked to North Korean Hackers Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire RatHat Android Trojan Uses AI for AutomationCrowdSec Confirms Source Code Stolen in Supply Chain AttackOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesTigerByte Cyber Emerges From Stealth With $3 Million in FundingNightmareStresser DDoS Service Disrupted in International OperationBrevo Supply Chain Attack Injects Malware Into 100,000 WebsitesCritical Orkes Conductor Vulnerability Exploited in AttacksMIND Secures $72 Million for AI-Powered DLP Latest News Recent ZyXEL Switch Vulnerability Exploited by Chinese HackersWordPress Patches ‘Click2Shell’ VulnerabilityJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider SchemeUS Proposes AI Incident Alert System in Talks With China, Bessent SaysGoogle Hit With $463 Million Fine for EU Location Data Rule BreachFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerCISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastDragos Completes NetRise and runZero Acquisitions Following Accenture Deal Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- domain — slack.com
- domain — telegram.org
- url — https://sepolia.etherscan.io/