[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhejKs2HQCwQ7DOQTYw15Re39h7UNEzNcW-GugkYRUFw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"d0ed024e-8cb1-487f-b2e9-21bdb2ec6675","malicious-npm-package-hides-loader-in-runtime-code-earns-230k","bdfe920e-8e16-47fc-94e3-36837084a959","Malicious npm Package Hides Loader in Runtime Code, Earns €230K","The 'indexed-btree' npm package demonstrates a sophisticated supply chain attack where malicious code was embedded directly into library runtime functions rather than lifecycle scripts, deliberately circumventing npm's newer security controls. Millions of downloads occurred before the package was detected and removed, highlighting how slow or absent code inspection of third-party dependencies creates massive exposure windows. This tactic shift — from install-time execution to runtime execution — shows attackers actively adapting to platform-level defenses, making static policy controls insufficient on their own. The financial impact (€230,000+ in cryptocurrency) underscores that supply chain attacks are highly profitable, incentivizing continued investment by threat actors. Organizations that blindly trust package download counts or registry presence as proxies for legitimacy remain critically vulnerable.","**Immediate actions:**\n- Audit all current npm dependencies against known malicious package databases such as OSV, Snyk Advisor, and Socket.dev.\n- Pin dependency versions in `package-lock.json` or `yarn.lock` and reject unapproved package updates until reviewed.\n- Remove or quarantine any instances of 'indexed-btree' and rotate credentials or tokens accessible from affected environments.\n\n**Long-term improvements:**\n- Integrate software composition analysis (SCA) tools (e.g., Snyk, FOSSA, Dependabot) into CI\u002FCD pipelines to flag new or updated dependencies before deployment.\n- Establish an internal approved-package registry or mirror that vets third-party libraries before they reach developer workstations.\n- Train developers to evaluate package legitimacy beyond download counts, including author history, repository activity, and code review.\n\n**Detection measures:**\n- Implement runtime application monitoring to detect unexpected outbound network calls originating from third-party library code.\n- Enable npm audit and automated SBOM (Software Bill of Materials) generation on every build to maintain a live inventory of all transitive dependencies.\n- Set up alerting for newly introduced or updated packages in pull requests to trigger mandatory security review workflows.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST SP 800-218 (SSDF): PW.4 – Reuse Existing, Well-Secured Software","NIST CSF DE.CM-8: Vulnerability Scans","SLSA Framework Level 2+: Source and Build Integrity","OWASP A06:2021 – Vulnerable and Outdated Components","ISO\u002FIEC 27001:2022 – Annex A 8.30: Outsourced Development","GDPR Article 32: Security of Processing (indirect risk via data exfiltration)","published","2026-09-22T13:21:42.572759+00:00","2026-09-22T13:21:42.265+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fmalicious-npm-package-indexed-btree-hid.html","malicious-npm-package-indexed-btree-hid-its-loader-in-runtime-code-before-remova-9806c6","Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]