Back to advisories

Malicious npm packages evade install-script defenses at runtime

Threat actors are distributing malware via npm packages that bypass install-script detection by executing malicious code at runtime instead. The 'indexed-btree' package and likely others in this campaign exfiltrate system data via Slack/Telegram and use Ethereum smart contracts for C2. Any developer or pipeline using compromised npm packages can be backdoored.

CRITICALAdvisorySep 22, 2026
Action required
Audit npm package dependencies immediately for 'indexed-btree' and similar suspicious packages. Review npm audit logs for installs in the past 90 days. Block execution of unknown npm packages in build pipelines and apply strict package verification policies going forward.
Affected products
indexed-btreesorted-btree